PayloadKit

FDE FileVault

com.apple.MCX.FileVault2

The payload that configures FileVault.

macOS
macOS 10.9+undefined

Configuration Keys (14)

KeyTypeTitle
Enablerequired

Set to 'On' to enable FileVault and set to 'Off' to disable FileVault. Payloads set to 'On' sent through MDM need to either include full authentication information in the payload or have the 'Defer' option set to 'true'. When 'Defer' is 'true', the system prompts for the authentication information when the user enables FileVault.

Range: On, Off

stringEnable FileVault 2
Defer

If 'true', the system defers enabling FileVault until the designated user logs out. For details, see 'fdesetup(8)'. Only a local user or a mobile account user can enable FileVault.

Default: false

booleanDefer enabling until logout
UserEntersMissingInfo

If 'true', the system enables a prompt for missing user name or password fields.

Default: false

booleanUser enters username and password
UseRecoveryKey

If 'true', the system creates a personal recovery key and displays it to the user.

Default: true

booleanCreate a personal recovery key
ShowRecoveryKey

If 'false', the system prevents display of the personal recovery key to the user after the system enables FileVault.

Default: true

booleanShow the personal recovery key
OutputPath

The path to the location of the recovery key and computer information property list.

stringRecovery key path
Certificate

The DER-encoded certificate data if the system creates an institutional recovery key. This key isn't supported on a Mac with Apple silicon.

dataCertificate
PayloadCertificateUUID

The UUID of the payload within the same profile containing the asymmetric recovery key certificate payload.

stringRecovery Key Certificate Payload
Username

The user name of the Open Directory user to add to FileVault.

stringUsername
Password

The password of the Open Directory user to add to FileVault. Use the 'UserEntersMissingInfo' key to prompt for this information.

stringPassword
UseKeychain

If 'true' and you don't include certificate information in this payload, the system uses the keychain created at '/Library/Keychains/FileVaultMaster.keychain' when it adds the institutional recovery key.

Default: false

booleanAdd institutional recovery key to keychain
DeferForceAtUserLoginMaxBypassAttempts

The maximum number of times users can bypass enabling FileVault before the system requires the user to enable it to log in. If the value is '0', the system requires the user to enable FileVault the next time they attempt to log in. Set this key to '-1' to disable this feature.

Range: -1 – 9999

integerMaximum number of times FileVault can be skipped
DeferDontAskAtUserLogout

If 'true', the system prevents requests to enable FileVault at user logout time.

Default: false

booleanDont ask at logout
ForceEnableInSetupAssistant

If 'true', and installation of this payload occurs after enrolling with MDM in Setup Assistant, the system requests Setup Assistant to enable FileVault at setup time. To use this, enable the Await Device Configured DEP configuration option and send this profile with this key set, before sending the 'DeviceConfiguredCommand'. An admin SecureToken user is required, otherwise the FileVault pane does not appear.

Default: false

boolean