N1 Technical note · macOS · Intune · FileVault
macOS enrollment and FileVault support guide
This guide helps locate where a Mac stopped: enrollment, policy delivery, FileVault, or recovery-key handling.
- Type
- Source-cited technical note
- Basis
- Official vendor documentation
- Review
- Primary-source technical review
- Visuals
- Clearly labelled diagrams and worksheets
- macOS
- Microsoft Intune guidance
- Apple deployment guidance
Support scenario
A Mac is not receiving policy, or the user cannot unlock the disk. Where did the process stop?
My role: I used Microsoft and Apple deployment guidance to map the support checkpoints shown here. This is a source-based guide, not a managed-tenant lab.
Enrollment flow
Enrollment and encryption are separate decisions.
- 01
Ownership
Personal or organization-owned
Use the approved enrollment path - 02
MDM registration
Profile and Company Portal state
Tenant or APNs owner if incomplete - 03
FileVault
Encryption and unlock-user state
Do not change without recovery plan - 04
Recovery key
Escrow confirmation only
Never publish or expose the key
Support path
Separate enrollment state from encryption state before changing either.
- 01
Confirm who owns the Mac and which enrollment method should apply. Personal enrollment, Automated Device Enrollment, and direct enrollment have different prerequisites.
- 02
Check that the Apple MDM push certificate is active. For Company Portal enrollment, confirm that the user approved the management profile and returned to Company Portal to finish registration.
- 03
Treat FileVault as a separate check. Confirm the encryption state, whether the account can unlock the volume, and whether an approved recovery key is escrowed.
- 04
Stop before removing management, wiping the Mac, displaying a recovery key, or changing encryption without authorization and a recovery plan.
Explanatory aids
Diagrams and worksheets tied to the source guidance.
The records below explain the support path. They are examples, not screenshots or output from a managed Mac.
- 01
- Confirm device ownership
- 02
- Identify the approved enrollment method
- 03
- Check MDM registration
- 04
- Check policy receipt
- 05
- Check FileVault and key escrow separately
- Enrollment method
- Expected or unknown
- Management profile
- Present or missing
- Registration
- Complete or incomplete
- FileVault
- On, off, or unknown
- Recovery-key escrow
- Confirmed or not confirmed
- Profile removal
- Confirm authorization and recovery plan first
- Recovery key
- Do not display or rotate it without approval
- FileVault change
- Confirm the recovery path before changing encryption
- Erase or reenroll
- Stop until ownership and data risk are understood
Primary sources
Result and limits
What this note supports, and what it does not claim.
Supports
The note identifies the next safe check and makes the handoff boundary explicit.
Limit
This is a cited technical note. It does not claim that I enrolled a Mac, administered a tenant, or recovered a live device.
Sources
Each conclusion points back to a cited source.
The workflow is based on cited vendor guidance.
Sources: Deployment guide: Enroll macOS devices in Microsoft Intune; Manage FileVault with device management