Manage FileVault with Sophos Central
Sophos Central Device Encryption manages Apple FileVault and the personal recovery key. macOS continues to provide the actual encryption, user enablement and pre-boot sign-in.
Requirements
Before rollout, ensure:
- a current macOS version supported by Sophos,
- correctly installed Endpoint and Device Encryption agents,
- the initial FileVault and MDM state is known,
- the user has the required Secure Token permission,
- Bootstrap Token and MDM profiles are correct on managed Macs,
- no competing FileVault management is active.
Pilot Intel and Apple Silicon Macs, and different enrolment methods, separately.
Activation
After the policy is assigned, Sophos may prompt the user for their password. This user interaction is required so that macOS can enable FileVault for an authorised account.
An ignored prompt leaves activation pending. The administrator therefore checks user communication and completion status as well as the policy.
During the initial rollout, Sophos automatically adds the existing local users to FileVault. After the system volume, unencrypted internal data volumes are also encrypted and unlocked automatically at startup. If an internal volume is already protected by its own disk password, enter it once during adoption so that Central can take over management. Remote sign-in isn’t sufficient for activation or migration.
FileVault users
Only authorised users can unlock the Mac at pre-boot. Creating a macOS account alone may not be sufficient when a new user is added. Check Secure Token, Volume Owner and FileVault permissions.
If the new user is not enabled for FileVault automatically, they sign in locally, enter their macOS sign-in password in the Sophos dialog and select Proceed. If no recovery key is stored in Central yet, an already authorised FileVault user must also be selected. That user authorises the operation with their own macOS sign-in password. Only then is it verified that the new user can actually unlock the Mac at pre-boot.
For shared Macs, document which accounts have pre-boot access. Remove obsolete users and leavers in a controlled manner.
Recovery key
Sophos Central stores the personal FileVault recovery key when management has been adopted correctly. Release the key only to an authorised person after identity verification.
After a recovery event, rotate the key according to the supported process. If Central continues to report a recovery-key error, check local FileVault management, agent communication, user permissions and existing MDM escrow settings.
If the agent can store the recovery key neither in the macOS keychain nor in Central, it displays the key to the user as emergency information. A backup accessible only to root may also exist at /Library/Application Support/Sophos Encryption/.RecoverykeyEmergencybackup. The agent continues trying to transfer the key to Central and informs the user after successful escrow. Do not use this local emergency key as a normal, permanently distributed recovery process.
Adopt existing FileVault
If FileVault is already active, first determine who manages the recovery key. Adoption is complete only when Central reports a valid key and the recovery process has been tested.
Do not discard an old institutional or personal key prematurely. A documented recovery route must remain available throughout migration.
Unlock APFS and recover
In macOS Recovery, an APFS volume can be unlocked using an authorised user or recovery key. The exact procedure depends on the macOS version and hardware.
During normal helpdesk recovery, the recovery key ID only appears on the startup screen for a few minutes; restart the Mac to display it again. After entering the key obtained from Central, the user creates a new sign-in password. For users imported from Active Directory, first reset the password in AD and issue a temporary password. Select Cancel in the macOS dialog and then enter that temporary password. If macOS prompts for it, create a new keychain afterwards.
After access is restored, investigate the cause of recovery rather than simply continuing: a user change, token problem, hardware change, OS upgrade or suspected tampering.
Read local status
The Sophos Device Encryption app displays policy, user, volume and recovery status. Green means fully encrypted with the key stored centrally. Yellow can indicate full encryption without a key stored in Central; red means that an active policy requires encryption but the volume is not encrypted.
Depending on the installed version, /usr/local/bin/seadmin is available for scripts. The local help for the installed agent version is authoritative.
Deactivation and device transfer
Before transferring a device or uninstalling, decide whether FileVault should remain active, move to another management platform or be decrypted. Removing the Sophos agent is not a documented key-migration process.
Confirm the final valid recovery state before removing the device from Central and handle it according to the retention process.
Missing recovery keys or keys invalidated by user or Apple ID changes are covered in Systematically troubleshoot Sophos Device Encryption.