Security

FileVault

The built-in macOS feature that encrypts the startup disk. Recovery access should be planned before it is enabled, especially on a shared or business-owned Mac.

How it works

FileVault adds access protection for a Mac’s startup data through disk encryption and authorized unlocking. Its relationship with hardware encryption depends on the Mac model: modern Apple hardware can already encrypt storage, while FileVault strengthens how access to that data is protected. It is not simply a password on a folder.

A practical example

A Mac that is lost or taken apart poses a different problem from one already unlocked for everyday work. FileVault concerns protection of stored data against unauthorized access. It does not prevent someone using an authorized unlocked session from reading files permitted to that account.

What to check

Check FileVault status in the supported macOS settings and confirm which users can unlock the disk. Before changing passwords or performing maintenance, verify the chosen recovery method and keep any recovery key securely accessible outside the locked computer. On organization-managed Macs, ask the administrator about the applicable recovery arrangements.

Limits and safe use

Encryption does not create a backup or repair storage damage. Losing all valid unlock and recovery methods may prevent access to the files. Do not disable FileVault merely to avoid planning recovery, and do not erase a locked Mac without understanding the data consequences. Exact options vary by hardware, macOS version and management policy.

Technical sources

← All glossary terms