Maintenance and security

FileVault and account security

Protect the startup disk, keep a recoverable account, and understand the consequence of losing every recovery method.

8 minute lesson

~~~

FileVault encrypts the startup volume so someone without an authorized login or recovery method cannot read its data by removing or directly accessing the disk.

Turn it on from System Settings → Privacy & Security → FileVault. Keep the Mac connected to power while initial encryption completes.

Recovery is part of encryption

macOS offers a recovery method. Store it somewhere separate from the Mac and test that the responsible person knows where to find it.

If every authorized password and recovery method is lost, the encryption is doing its job: the data may be unrecoverable. Do not enable FileVault on a shared or business Mac without deciding who owns recovery.

Before changing account passwords or removing an account, confirm that another authorized recovery path remains.

Protect the unlocked session

Disk encryption mainly protects data when the Mac is locked or powered off. It cannot protect files from someone using an already unlocked session.

Use a strong, unique login password. Require the password promptly after sleep or the screen saver. Do not enable automatic login on a Mac containing sensitive data.

Keep separate accounts for separate people. An administrator account can change more of the system, so use a standard account for everyday work when that fits your setup.

FileVault does not replace backups. An encrypted disk can still fail, and encrypted files can still be deleted or corrupted while you are signed in.

Try this: without changing settings, review whether FileVault is enabled, which accounts can unlock the disk, where recovery is stored, and whether the Mac locks automatically.

Lesson completed

Take this course offline

Get every free book and course as PDF and EPUB files.

Get the download library →