How to Turn On FileVault and Encrypt Your Mac

A shut-down Mac with FileVault holds no more readable data than a lump of metal.

By Abigail Shilets - Staff Writer
4 Min Read

FileVault prevents access to your Mac at startup without the password for an account with permission to boot the computer. Instead of loading macOS, enabling FileVault has your Mac pass control after startup to a very simple program that resembles the standard macOS login window. Entering a valid account password on this screen allows that program to access the encryption key to unlock the startup disk and proceed seamlessly (and invisibly) into your regular Mac session. Because FileVault is integrated into macOS at such a deep level, there’s only an on/off button. You don’t need to manage any of the parts.

On Macs without a T2 chip or Apple silicon processor, FileVault also performs full-disk encryption (often called FDE). But that’s automatic and cannot be turned off on T2/Apple silicon Macs.

Starting in macOS 26 Tahoe, FileVault is automatically enabled for all users in new installations and via upgrades. It can be disabled; read on to find out if you have a reason to do so. If you didn’t previously have FileVault enabled, the first time you start up in Tahoe, you will see a message that “Your Mac is [sic] Protected by FileVault.” The dialog further explains that the Passwords app has the critical Recovery Key (see where to find your FileVault Recovery Key).

Apple also got rid of a lingering potential path for crackers and government intrusion by switching from relatively insecure storage in iCloud to fully secure storage. This is welcome!

Should you ever disable FileVault?

FileVault is an additional protection for all users that prevents unwanted access to their data. However, despite my strong recommendation to enable it, it is overkill for some people that could result in them losing access to their data in specific circumstances.

What are those circumstances?

First, they would have to either be unable to remember or find their macOS account password, or the FileVault login data for accounts would have to become corrupt and reject a legitimate password.

Second, they then couldn’t find or gain access to their FileVault Recovery Key, discussed in where to find your FileVault Recovery Key.

Most people enter their macOS account password routinely and are unlikely to forget it. But it is the case that you can experience a problem that scrambles the normal startup FileVault login. If so, your FileVault Recovery Key is your only hope. If that becomes irretrievable, you’re sunk.

So before you proceed, consider if protection for your data when the computer is turned off is worth the risk of disabling FileVault.

How startup encryption works

Full-disk encryption puts a layer between the operating system and a storage drive that automatically decrypts all information coming off the drive and encrypts it as it’s written. This means all information on the drive “at rest” is fully encrypted.

Only while a Mac is active is stored information vulnerable to interception: macOS holds the encryption key in memory to allow it to encrypt and decrypt data on the fly. This allows a Mac to treat an encrypted volume as if it were effectively not encrypted at all while the volume is in use, including letting you share the volume over a network and back it up to an external drive, a networked volume, or an internet service, and use sync services like Dropbox, iCloud Drive, and OneDrive.

Whenever a Mac is shut down, a drive is an inaccessible vault, with no more information accessible than a lump of solid metal. The key material necessary to decrypt its data can’t be accessed.

The introduction of the T2 chip, and, later, Apple silicon, removed all overhead, and Apple made the decision for security reasons that FDE is always enabled on T2/Apple silicon Macs, even if FileVault is not. This also means T2/Apple silicon Macs can enable or disable FileVault in seconds, if desired.

However, without FileVault enabled, the drive is automatically decrypted on startup even before an account password is entered! That’s the piece that FileVault fills in.

With an Apple silicon Mac, the startup process without FileVault begins with operations that retrieve the security key, which is mediated by the Secure Enclave. If the SSD drive is removed from the Mac, which in modern Macs is difficult enough to be infeasible, the decryption information remains in the Secure Enclave left behind. It seems unlikely a thief or corporate or government spy would take the drive and not the whole computer, however.

Additional protections available in Apple silicon, combined with changes in macOS (starting back in Big Sur), allow that Mac to unlock the system files to boot directly into macOS without exposing any user data files.

Your data and Mac remain protected until a valid account password is entered, at which point the key protecting the data is made available for use, and startup proceeds. This may feel like enough for you. However, Apple seems to think it isn’t, and thus enables FileVault by default in Tahoe.

Encrypt external drives

You can also encrypt any mountable SSD, HDD, or disk image that is not configured as a macOS startup drive.

There are two primary ways to encrypt non-startup volumes:

  • Control-click or right-click in the Finder: This is the easiest method, and will take place in the background. Control-click or right-click the volume and choose Encrypt. Enter and verify a strong password, preferably one you generated in a password-management app. Add a hint if you think it will help. Click Encrypt Disk. This converts the drives in the Finder without losing any data. (Disk Utility, by contrast, can change a volume’s format type to the encrypted flavor, but it always erases the volume—and warns you before you proceed.)
  • Disk Utility for disk images: Disk Utility can also create encrypted disk images, though it uses a different method. Choose New Image > Blank Image, then choose 256-bit AES from the Encryption menu. You’re prompted to enter and verify a password, but not store a reminder tip. Set other parameters as needed and click Save to create the image.

In the future, you have to enter the password for a volume to mount an encrypted volume or disk image in the Finder or to access it via Disk Utility. When mounted, the drive appears as fully decrypted to the Finder, just like a startup volume with FileVault, and can be shared, synced, and backed up.

Apple notes carefully that passwords created for any encrypted drive other than the startup volume aren’t managed in the Secure Enclave. You have to manage them yourself, and they don’t come with the same high level of protection.

Apple will no longer support Encrypted HFS+ after Golden Gate. If you have an HFS+ volume you encrypted in a previous macOS release, this is the time to remove encryption or upgrade the volume to APFS. You can perform both operations in Disk Utility.

Staff Writer
Follow:
Abigail is a staff writer for GeeksChalk based in Pennsylvania. She covers news, how-tos, and user guides for iPhone, iPad, Mac, and Apple Watch. Before becoming a writer Abigail studied computer science at University and also worked at Apple for more than two years. When not creating masterpiece for GeeksChalk, you can usually find Abigail hiking, climbing, or otherwise unplugged.
Leave a Comment