FDE FileVault (com.apple.MCX.FileVault2)

com.apple.MCX.FileVault2

The payload that configures FileVault.

macOS(10.9)
Branch: release

Settings (14)

SettingTypeRequiredDefaultManual InstallSupported OS
Enable
Enable
Set to `On` to enable FileVault and set to `Off` to disable FileVault. Payloads set to `On` sent through MDM need to either include full authentication information in the payload or have the `Defer` option set to `true`. When `Defer` is `true`, the system prompts for the authentication information when the user enables FileVault.
stringrequired—
✓Yes
macOS (10.9+)
Defer
Defer
If `true`, the system defers enabling FileVault until the designated user logs out. For details, see `fdesetup(8)`. Only a local user or a mobile account user can enable FileVault.
booleanoptionalfalse
✓Yes
macOS (10.9+)
UserEntersMissingInfo
UserEntersMissingInfo
If `true`, the system enables a prompt for missing user name or password fields.
booleanoptionalfalse
✓Yes
macOS (10.9+)
UseRecoveryKey
UseRecoveryKey
If `true`, the system creates a personal recovery key and displays it to the user.
booleanoptionaltrue
✓Yes
macOS (10.9+)
ShowRecoveryKey
ShowRecoveryKey
If `false`, the system prevents display of the personal recovery key to the user after the system enables FileVault.
booleanoptionaltrue
✓Yes
macOS (10.9+)
OutputPath
OutputPath
The path to the location of the recovery key and computer information property list.
stringoptional—
✓Yes
macOS (10.9+)
Certificate
Certificate
The DER-encoded certificate data if the system creates an institutional recovery key. This key isn't supported on a Mac with Apple silicon.
dataoptional—
✓Yes
macOS (10.9+)
PayloadCertificateUUID
PayloadCertificateUUID
The UUID of the payload within the same profile containing the asymmetric recovery key certificate payload.
stringoptional—
✓Yes
macOS (10.9+)
Username
Username
The user name of the Open Directory user to add to FileVault.
stringoptional—
✓Yes
macOS (10.9+)
Password
Password
The password of the Open Directory user to add to FileVault. Use the `UserEntersMissingInfo` key to prompt for this information.
stringoptional—
✓Yes
macOS (10.9+)
UseKeychain
UseKeychain
If `true` and you don't include certificate information in this payload, the system uses the keychain created at `/Library/Keychains/FileVaultMaster.keychain` when it adds the institutional recovery key.
booleanoptionalfalse
✓Yes
macOS (10.9+)
DeferForceAtUserLoginMaxBypassAttempts
DeferForceAtUserLoginMaxBypassAttempts
The maximum number of times users can bypass enabling FileVault before the system requires the user to enable it to log in. If the value is `0`, the system requires the user to enable FileVault the next time they attempt to log in. Set this key to `-1` to disable this feature.
Range: -1 - 9999
integeroptional—
✓Yes
macOS (10.9+)
DeferDontAskAtUserLogout
DeferDontAskAtUserLogout
If `true`, the system prevents requests to enable FileVault at user logout time.
booleanoptionalfalse
✓Yes
macOS (10.10+)
ForceEnableInSetupAssistant
ForceEnableInSetupAssistant
If `true`, and installation of this payload occurs after enrolling with MDM in Setup Assistant, the system requests Setup Assistant to enable FileVault at setup time. To use this, enable the Await Device Configured ADE configuration option and send this profile with this key set, before sending the `DeviceConfiguredCommand`. An admin SecureToken user is required, otherwise the FileVault pane doesn't appear.
booleanoptionalfalse
✗No
macOS (14.0+)

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information