Enable the option to use personal recovery key to encrypt user's mac systems.Enter a name for the profile and select FileVault Encryption.On the MDM console, navigate to Device Mgmt ->Apple profile.Since the personal recovery key is specific to users, this also prevents any unauthorized use of the recovery key.įollow the steps given here to encrypt data using personal recovery key. This ensures the users can request their organization's IT admins to provide them the recovery key to access their data. The recovery key generated during encryption can then be posted to the Mobile Device Manager Plus server. Mobile Device Manager Plus supports encryption using a recovery key. If the user forgets his login password the user will be prompted to enter this generated recovery key to decrypt his system. Personal and institutional recovery keyįilevault allows users to generate a personal recovery key that can be used to access their encrypted data in addition to their login credentials.Using Mobile Device Manager Plus, a Mac system can be encrypted using any of the following methods Simplified set up procedure- The user has to just choose the method of encryption, enable and upload a certificate to complete the setup process.Keys stored in the server- The user does not have to be tasked with remembering the personal recovery key if they forget their passwords.Enforced encryption- The admin of the organization can ensure that encryption is enforced on all the required systems using the desired encryption methods.No user dependency- Once the admin creates the profile and applies it to the devices, the encryption process will begin when the device is logged in the next time, without any user intervention.One time setup- You need to create and distribute the profile to groups only once, and all the devices will be encrypted.Using Mobile Device Manager Plus to perform FileVault encryption on Mac machines also has the following benefits This ensures uniformity in the encryption process used and also that all the users have encrypted their devices. Though users can manually encrypt their systems, it is always recommended to use a device management solution to encrypt the managed systems. Encryption using institutional recovery keyĮncryption using Mobile Device Manager Plus.It provides two methods for encrypting the data on the systems.
The users authenticate themselves with their login credentials, which in turn decrypts the information for access.įilevault is the most preferred tool for encrypting the data on mac machines. Encryption ensures that the information on these computers can only be accessed by authorized users. This feature is available in Professional, Free, and Trial editions of MDMĮncrypting information stored in employee computers is mandated in most organizations.