{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-305-bring-an-already-encrypted-mac-under-intune-filevault-management/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-305-bring-an-already-encrypted-mac-under-intune-filevault-management/",
        "slug": "dse-20260909-305-bring-an-already-encrypted-mac-under-intune-filevault-management",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-305-bring-an-already-encrypted-mac-under-intune-filevault-management/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-305-bring-an-already-encrypted-mac-under-intune-filevault-management.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-305-bring-an-already-encrypted-mac-under-intune-filevault-management/"
        },
        "title": "Bring an already encrypted Mac under Intune FileVault management",
        "summary": "What must happen before Intune can manage a Mac that was encrypted before its FileVault policy arrived?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:51+00:00",
        "modified_at": "2026-09-10T01:40:02+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 243,
        "potentially_affected": "Review this path for a previously encrypted Mac joining the managed fleet. Confirm device access, applicable enrollment requirements, policy delivery, and the user's ability to supply or regenerate the key before scheduling the handoff.",
        "dse_recommendation": "Treat encryption state and management adoption as separate acceptance items.",
        "primary_source": {
            "name": "Encrypt macOS devices with FileVault using Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-configuration/endpoint-security/encrypt-filevault-macos",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Intune can take over management of FileVault encryption that a user enabled before receiving its policy. Both documented adoption methods require an active Intune FileVault policy. A user who knows the current recovery key can upload it through Company Portal; Intune validates it, rotates it, and escrows the replacement. The alternative generates a new key on the device before check-in. <a href=\"https://learn.microsoft.com/en-us/intune/device-configuration/endpoint-security/encrypt-filevault-macos\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review this path for a previously encrypted Mac joining the managed fleet. Confirm device access, applicable enrollment requirements, policy delivery, and the user&#8217;s ability to supply or regenerate the key before scheduling the handoff.</p>\n<h2>DSE recommendation</h2>\n<p>Treat encryption state and management adoption as separate acceptance items. Select the documented method with the device owner, arrange a protected recovery-key handling path, and preserve access to the device while verifying the newly escrowed current key. Do not plan to recover with the previous key after rotation. Do not ask users to paste recovery material into a support ticket or infer successful adoption from an encrypted-disk indicator.</p>\n<h2>Verification</h2>\n<p>After the chosen procedure, verify the encryption report and recovery-key availability through the documented user retrieval path. Confirm that the user can identify the correct device and retrieve its current key using the approved process. Keep only sanitized outcomes in the change record. If policy delivery or retrieval is unresolved, leave the management handoff open rather than declaring the device fully onboarded.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-configuration/endpoint-security/encrypt-filevault-macos\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Encrypt macOS devices with FileVault using Intune</a>.</p>",
        "content_text": "Source facts\nIntune can take over management of FileVault encryption that a user enabled before receiving its policy. Both documented adoption methods require an active Intune FileVault policy. A user who knows the current recovery key can upload it through Company Portal; Intune validates it, rotates it, and escrows the replacement. The alternative generates a new key on the device before check-in. Microsoft Learn.\nApplicability\nReview this path for a previously encrypted Mac joining the managed fleet. Confirm device access, applicable enrollment requirements, policy delivery, and the user’s ability to supply or regenerate the key before scheduling the handoff.\nDSE recommendation\nTreat encryption state and management adoption as separate acceptance items. Select the documented method with the device owner, arrange a protected recovery-key handling path, and preserve access to the device while verifying the newly escrowed current key. Do not plan to recover with the previous key after rotation. Do not ask users to paste recovery material into a support ticket or infer successful adoption from an encrypted-disk indicator.\nVerification\nAfter the chosen procedure, verify the encryption report and recovery-key availability through the documented user retrieval path. Confirm that the user can identify the correct device and retrieve its current key using the approved process. Keep only sanitized outcomes in the change record. If policy delivery or retrieval is unresolved, leave the management handoff open rather than declaring the device fully onboarded.\nOfficial references\nMicrosoft Learn: Encrypt macOS devices with FileVault using Intune.",
        "content_markdown": "## Source facts\n\nIntune can take over management of FileVault encryption that a user enabled before receiving its policy. Both documented adoption methods require an active Intune FileVault policy. A user who knows the current recovery key can upload it through Company Portal; Intune validates it, rotates it, and escrows the replacement. The alternative generates a new key on the device before check-in. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-configuration/endpoint-security/encrypt-filevault-macos).\n\n## Applicability\n\nReview this path for a previously encrypted Mac joining the managed fleet. Confirm device access, applicable enrollment requirements, policy delivery, and the user’s ability to supply or regenerate the key before scheduling the handoff.\n\n## DSE recommendation\n\nTreat encryption state and management adoption as separate acceptance items. Select the documented method with the device owner, arrange a protected recovery-key handling path, and preserve access to the device while verifying the newly escrowed current key. Do not plan to recover with the previous key after rotation. Do not ask users to paste recovery material into a support ticket or infer successful adoption from an encrypted-disk indicator.\n\n## Verification\n\nAfter the chosen procedure, verify the encryption report and recovery-key availability through the documented user retrieval path. Confirm that the user can identify the correct device and retrieve its current key using the approved process. Keep only sanitized outcomes in the change record. If policy delivery or retrieval is unresolved, leave the management handoff open rather than declaring the device fully onboarded.\n\n## Official references\n\n[Microsoft Learn: Encrypt macOS devices with FileVault using Intune](https://learn.microsoft.com/en-us/intune/device-configuration/endpoint-security/encrypt-filevault-macos)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-305-bring-an-already-encrypted-mac-under-intune-filevault-management/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-305-bring-an-already-encrypted-mac-under-intune-filevault-management/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-305-bring-an-already-encrypted-mac-under-intune-filevault-management/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Bring an already encrypted Mac under Intune FileVault management",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-305-bring-an-already-encrypted-mac-under-intune-filevault-management/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-305-bring-an-already-encrypted-mac-under-intune-filevault-management/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-305-bring-an-already-encrypted-mac-under-intune-filevault-management/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-305-bring-an-already-encrypted-mac-under-intune-filevault-management/",
                "headline": "Bring an already encrypted Mac under Intune FileVault management",
                "description": "What must happen before Intune can manage a Mac that was encrypted before its FileVault policy arrived?",
                "abstract": "What must happen before Intune can manage a Mac that was encrypted before its FileVault policy arrived?",
                "articleBody": "Source facts\nIntune can take over management of FileVault encryption that a user enabled before receiving its policy. Both documented adoption methods require an active Intune FileVault policy. A user who knows the current recovery key can upload it through Company Portal; Intune validates it, rotates it, and escrows the replacement. The alternative generates a new key on the device before check-in. Microsoft Learn.\nApplicability\nReview this path for a previously encrypted Mac joining the managed fleet. Confirm device access, applicable enrollment requirements, policy delivery, and the user’s ability to supply or regenerate the key before scheduling the handoff.\nDSE recommendation\nTreat encryption state and management adoption as separate acceptance items. Select the documented method with the device owner, arrange a protected recovery-key handling path, and preserve access to the device while verifying the newly escrowed current key. Do not plan to recover with the previous key after rotation. Do not ask users to paste recovery material into a support ticket or infer successful adoption from an encrypted-disk indicator.\nVerification\nAfter the chosen procedure, verify the encryption report and recovery-key availability through the documented user retrieval path. Confirm that the user can identify the correct device and retrieve its current key using the approved process. Keep only sanitized outcomes in the change record. If policy delivery or retrieval is unresolved, leave the management handoff open rather than declaring the device fully onboarded.\nOfficial references\nMicrosoft Learn: Encrypt macOS devices with FileVault using Intune.",
                "datePublished": "2026-09-10T00:26:51+00:00",
                "dateModified": "2026-09-10T01:40:02+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-305-bring-an-already-encrypted-mac-under-intune-filevault-management/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-305-bring-an-already-encrypted-mac-under-intune-filevault-management/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Bring an already encrypted Mac under Intune FileVault management"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 243,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Encrypt macOS devices with FileVault using Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-configuration/endpoint-security/encrypt-filevault-macos"
                }
            }
        ]
    }
}