Gary VirkIT Specialist
← All work

N1 Technical note · macOS · Intune · FileVault

macOS enrollment and FileVault support guide

This guide helps locate where a Mac stopped: enrollment, policy delivery, FileVault, or recovery-key handling.

DecisionThe next action depends on where the enrollment or encryption path stopped and whether device-owner or administrator approval is required.
Type
Source-cited technical note
Basis
Official vendor documentation
Review
Primary-source technical review
Visuals
Clearly labelled diagrams and worksheets
  • macOS
  • Microsoft Intune guidance
  • Apple deployment guidance

A Mac is not receiving policy, or the user cannot unlock the disk. Where did the process stop?

My role: I used Microsoft and Apple deployment guidance to map the support checkpoints shown here. This is a source-based guide, not a managed-tenant lab.

Enrollment and encryption are separate decisions.

  1. 01

    Ownership

    Personal or organization-owned

    Use the approved enrollment path
  2. 02

    MDM registration

    Profile and Company Portal state

    Tenant or APNs owner if incomplete
  3. 03

    FileVault

    Encryption and unlock-user state

    Do not change without recovery plan
  4. 04

    Recovery key

    Escrow confirmation only

    Never publish or expose the key

Separate enrollment state from encryption state before changing either.

  1. 01

    Confirm who owns the Mac and which enrollment method should apply. Personal enrollment, Automated Device Enrollment, and direct enrollment have different prerequisites.

  2. 02

    Check that the Apple MDM push certificate is active. For Company Portal enrollment, confirm that the user approved the management profile and returned to Company Portal to finish registration.

  3. 03

    Treat FileVault as a separate check. Confirm the encryption state, whether the account can unlock the volume, and whether an approved recovery key is escrowed.

  4. 04

    Stop before removing management, wiping the Mac, displaying a recovery key, or changing encryption without authorization and a recovery plan.

Diagrams and worksheets tied to the source guidance.

The records below explain the support path. They are examples, not screenshots or output from a managed Mac.

01
Confirm device ownership
02
Identify the approved enrollment method
03
Check MDM registration
04
Check policy receipt
05
Check FileVault and key escrow separately
Explanatory aidEnrollment sequenceA step-by-step diagram showing where ownership, enrollment, management registration, compliance, and encryption checks separate.
Enrollment method
Expected or unknown
Management profile
Present or missing
Registration
Complete or incomplete
FileVault
On, off, or unknown
Recovery-key escrow
Confirmed or not confirmed
Explanatory aidSupport worksheetIllustrative checks to record before removing a profile or changing encryption. This is not captured device output.
Profile removal
Confirm authorization and recovery plan first
Recovery key
Do not display or rotate it without approval
FileVault change
Confirm the recovery path before changing encryption
Erase or reenroll
Stop until ownership and data risk are understood
Explanatory aidEscalation boundaryThe note stops before actions that can remove management, expose a recovery key, or risk the user's data.

Guidance used for this note.

What this note supports, and what it does not claim.

Supports

The note identifies the next safe check and makes the handoff boundary explicit.

Limit

This is a cited technical note. It does not claim that I enrolled a Mac, administered a tenant, or recovered a live device.

Each conclusion points back to a cited source.

Device ownership, MDM registration, FileVault status, and recovery-key handling must be checked separately.

The workflow is based on cited vendor guidance.

Sources: Deployment guide: Enroll macOS devices in Microsoft Intune; Manage FileVault with device management