It's completely normal for this process to take more than one day to complete. Is this normal behavior? Before you turn on FileVault, be aware that the initial encryption process can take hours to complete. Click Set up my iCloud account to reset my password if you dont already use iCloud. From the policy: ASSET CONTROL POLICY DETAILS Definition of assets Assets can be defined both PURPOSE This policy from TechRepublic Premium provides guidelines for the reporting of information security incidents by company employees. Erasing the media key in this manner renders the volume cryptographically inaccessible. You are using an out of date browser. On your Mac, choose Apple menu >System Settings, click Privacy & Security in the sidebar, then go to FileVault. 2023 Clario Tech DMCC. If you turn on FileVault and then forget your login password and cant reset it, and you also forget your recovery key, you wont be able to log in, and your files and settings will be lost forever. FileVault on a Mac with Apple silicon is implemented using Data Protection Class C with a volume key. Fresh out of the box, these have taken less than an hour to fully encrypt the whole drive. The current recovery key is displayed. For Escrow location description of personal recovery key, add a message to help guide users on how to retrieve the recovery key for their device. This is especially important if you share your Mac with other people, like co-workers or family members. How and Why to use FileVault Disk Encryption on Mac After the key is escrowed, the disk encryption can start. The device that has the personal recovery key must be enrolled with Intune and encrypted with FileVault through Intune. Copyright 2023 Apple Inc. All rights reserved. How does FileVault encryption work on a Mac? - Apple Support If FileVault is turned on latera process that is immediate since the data was already encryptedan anti-replay mechanism prevents the old key (based on hardware UID only) from being used to decrypt the volume. Sign in to the Intune Company Portal website from any device. Backup of encrypted data works seamlessly with Time Machine to create automated backup sets. Recovery key: The key is a string of letters and numbers thats created for you keep a copy of the key somewhere other than your encrypted startup disk. Read the WARNING. First, the device is prepared to enable Intune to retrieve and back up the recovery key. Upload of the key enables Intune to assume management of the encryption. SEE: Encryption Policy (Tech Pro Research). Important: After you turn on FileVault and the encryption begins, you cant turn off FileVault until the initial encryption is complete. Only data that resides on the local disk or FileVault 2-encrypted volumes may be encrypted in their entirety. Yes. Additionally, a master recovery key is created during the initial process; users with either of those keys may be the only ones to decrypt the volume and read the contents of the drive. Again, it is new out-of-the-box with < 15 GB of used disk space. Apples FileVault encryption program was initially introduced with OS X 10.3 (Panther), and it allowed for the encryption of a users home folder only. Teddy_B. Protect your Mac. Initiating a FileVault decryption on a T2 or M1 Mac usually won't take longer than 5 minutes, but it depends on your Mac's speed and capacity, your hard drive, and the used space on the disk.