Enable FileVault (whole disk encryption) on macOS 10.11 and higher
Primer
- FileVault in Mac OS X and macOS Sierra is based on a whole disk encryption (WDE) schema.
- This feature provides added security for data stored on a computer's disk.
Please consult with your System Administrator before enabling FileVault on your machine.
Instructions
- Navigate to System Preferences.
- Select Security & Privacy from the main System Preferences window.
- Choose the tab labeled FileVault and click the lock icon in the lower left-hand corner of the Security & Privacy window.
- When prompted, authenticate with your user account username and password.
- You will again find yourself at the Security & Privacy window. Click the button labeled Turn on FileVault....
- If there are multiple users accounts on this machine you will be prompted to give additional users access. All users that need the ability to use this machine should be given disk access-rights by clicking the button labeled Enable user..., entering that user's password, and clicking the button labeled Continue.
- The following screen will display the disk's recovery key. If a disk password is lost or forgotten this is the ONLY WAY to recover the data on the encrypted disk. Please write this 24 character string down and store it in a secure place. Click the button labeled Continue.
- You may also be asked to store the key in Casper. Select yes to have it stored with IS&T, who can then retrieve the key for you later. This is not required.
- OS X will display a prompt asking if you wish to store your recovery key with Apple. Select the radio button labeled Do not store the recovery key with Apple and click the button labeled Continue.
- OS X will now prompt you to restart to enable FileVault and begin the whole disk encryption process. Click Restart.
- The login process now takes place when OS X reboots. This authentication serves two purposes: it unlocks the disk and logs the selected user in.
- Upon reboot, the Security & Privacy window will open again and display the amount of time remaining until the disk is fully encrypted. The machine can be used during this time period.