GoLive gives you direct, real-time control over an individual device — including the ability to enable FileVault encryption remotely, with recovery keys automatically escrowed to Addigy.
Prerequisites
FileVault requires User-Approved MDM (UAMDM) on the device.
How to Enable FileVault via GoLive
- Navigate to the Devices page.
- Click the GoLive link or the device name to open the GoLive page for that device.
- Click the Security tab.
-
In the FileVault Encryption section, click Enable.
- A modal window appears explaining how FileVault will be enabled.
- Select Enable. Addigy attempts to enable FileVault on the device and escrows the recovery keys. Any errors that occur appear on screen.
Note: The end user can't stop FileVault once it's enabled. If you need to halt the process, run this command on the device before encryption begins:
fdesetup disable
Additional Information
- To disable FileVault after encryption has completed, see Decrypting Devices with FileVault.
- The user must log out to see the "Enable FileVault" prompt — rebooting or shutting down won't trigger it as it did on earlier macOS versions.
- Only users with SecureToken enabled can decrypt a device that has FileVault enabled. Users without SecureToken won't appear as options at the FileVault login window.
- For troubleshooting help, see Troubleshooting FileVault Enablement.