If a Mac was encrypted with FileVault outside of Addigy, Addigy never learns that recovery key on its own — there's no automatic way for it to find out. This article covers how to get a device's FileVault key escrowed to Addigy after the fact, either by generating a fresh key or by importing a key you already know.
Overview
When a device is encrypted with FileVault through Addigy, its recovery key escrows to the Addigy MDM server automatically (and can optionally show the end user a plain-text prompt). If the device was encrypted some other way, Addigy has no record of that key. Addigy has a documented manual process for exporting a key — creating a custom MDM payload and running the filevault-manager binary by hand — but that's tedious across more than a handful of devices, so this article covers two faster paths.
Option 1: Generate a New Key and Escrow It
If you don't need to preserve the device's existing recovery key, the fastest option is to have the device generate a new one and escrow it automatically.
Requirements
- The device is enrolled in Addigy MDM.
- An Addigy MDM Configuration with FileVault enabled is assigned to the device.
- The end user is available to enter their password (or equivalent).
Run the following on the device (it must be enrolled in Addigy MDM with a FileVault payload assigned, so Addigy knows where to escrow the resulting key):
sudo fdesetup changerecovery -personal
Note: This command replaces the device's current recovery key with a brand-new one and escrows that new key. It does not import or preserve the device's original key — use Option 2 if you need to keep a specific, already-known key.
Option 2: Import an Already-Known Key via Script
If you need to import a specific recovery key you already have on record — rather than generate a new one — use one of the two scripts attached to this article. Given a mapping of serial numbers to recovery keys, the script generates a unique MDM payload containing that key and uploads it to Addigy.
Note: The script must be run on the device whose key you're importing. That device needs access to whatever data source (a hardcoded value or a CSV file) supplies its recovery key.
-
fvEscrow.sh — for a single device. Set the script's
RecoveryKeyvariable to the known key, then run it on that device. - fvEscrowCSV.sh — for importing keys across many devices at once, using a CSV file that maps serial numbers to recovery keys.
Step 1: Prepare the CSV
The CSV's columns must be named exactly Serial and Recovery.
Step 2: Get the CSV onto Each Device
Since the script runs on the device itself, each device needs local access to the CSV. We recommend deploying the file via Smart Software — see Creating Smart Software for that workflow. Whichever method you use, make sure the script references the CSV's actual file path on the device (for example, /tmp).
Step 3: Deploy and Run the Script
Download the fvEscrowCSV.sh script attached to this article, and paste its contents into a new custom script on the Devices page. See Creating and Running Scripts on Your Devices if you're unfamiliar with that workflow. Select the target devices and run the script.
Step 4: Verify the Key Imported Successfully
Open GoLive for the device, select Security, and scroll to Keys under FileVault Encryption.
Download the key from there to confirm it matches what you expected.