Learn about macOS FileVault encryption

Overview

Mount Holyoke College requires that each MHC-owned notebook computer have native disk encryption enabled. On macOS, this function is provided by FileVault. Learn more about FileVault at Apple's website.

Issue

A computer may prompt to enable FileVault if its setup was not completed before deployment.

Resolution

Enable FileVault

  1. The computer will prompt to enable FileVault.
  2. The next time you restart your computer, you will enter your password (for the computer) normally. We recommend connecting the AC power cord if not connected already.
  3. After your password is accepted, you'll be notified that the computer administrators require FileVault to be enabled.
  4. Follow the prompts to enable FileVault.
  5. macOS will encrypt your data and generate a recovery key, to be used if you forget your computer password. 
  6. Record the recovery key when it is shown, but also know that our Mac management system securely stores a recovery key in escrow as well as a backup.
  7. This should take just a few moments on the next startup. 
     

Issue

Mac computer prompts for a recovery key

Resolution

Enter recovery key

If you enter the incorrect password for your Mac too many times, it may prompt you to log in using a recovery key. This was presented when FileVault was enabled. If you have a copy of the recovery key, you can enter it. If you don't,  you can contact the LITS Technology Support Helpdesk and ask for assistance. The LITS Mac management system stores recovery keys for MHC-owned computers, to make them available by LITS computer technicians.