# Bring an already encrypted Mac under Intune FileVault management

> What must happen before Intune can manage a Mac that was encrypted before its FileVault policy arrived?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-305-bring-an-already-encrypted-mac-under-intune-filevault-management/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:51+00:00
- Modified: 2026-09-10T01:40:02+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

What must happen before Intune can manage a Mac that was encrypted before its FileVault policy arrived?

## Potentially affected

Review this path for a previously encrypted Mac joining the managed fleet. Confirm device access, applicable enrollment requirements, policy delivery, and the user's ability to supply or regenerate the key before scheduling the handoff.

## DSE recommendation

Treat encryption state and management adoption as separate acceptance items.

## Article

## Source facts

Intune can take over management of FileVault encryption that a user enabled before receiving its policy. Both documented adoption methods require an active Intune FileVault policy. A user who knows the current recovery key can upload it through Company Portal; Intune validates it, rotates it, and escrows the replacement. The alternative generates a new key on the device before check-in. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-configuration/endpoint-security/encrypt-filevault-macos).

## Applicability

Review this path for a previously encrypted Mac joining the managed fleet. Confirm device access, applicable enrollment requirements, policy delivery, and the user’s ability to supply or regenerate the key before scheduling the handoff.

## DSE recommendation

Treat encryption state and management adoption as separate acceptance items. Select the documented method with the device owner, arrange a protected recovery-key handling path, and preserve access to the device while verifying the newly escrowed current key. Do not plan to recover with the previous key after rotation. Do not ask users to paste recovery material into a support ticket or infer successful adoption from an encrypted-disk indicator.

## Verification

After the chosen procedure, verify the encryption report and recovery-key availability through the documented user retrieval path. Confirm that the user can identify the correct device and retrieve its current key using the approved process. Keep only sanitized outcomes in the change record. If policy delivery or retrieval is unresolved, leave the management handoff open rather than declaring the device fully onboarded.

## Official references

[Microsoft Learn: Encrypt macOS devices with FileVault using Intune](https://learn.microsoft.com/en-us/intune/device-configuration/endpoint-security/encrypt-filevault-macos).

## Primary reference

- Name: Encrypt macOS devices with FileVault using Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-configuration/endpoint-security/encrypt-filevault-macos
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Bring an already encrypted Mac under Intune FileVault management,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-305-bring-an-already-encrypted-mac-under-intune-filevault-management/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
