How to Use macOS FileVault to Encrypt Your Startup Disk

If you lose your MacBook at a coffee shop, a password on your user account will not protect your data. A malicious actor can easily boot the Mac into Target Disk Mode or physically remove the internal drive (on older models) and read every document, photo, and saved password on the disk. To truly secure your data, you must encrypt the entire drive at the hardware level. Apple provides this capability natively through FileVault.

What is FileVault?

FileVault performs full-disk encryption using XTS-AES-128 cryptography with a 256-bit key. When your Mac is turned off, the data on the drive is mathematical gibberish. The data is only decrypted on-the-fly as it is loaded into RAM, and only after you successfully enter your login password when the computer first boots up.

Note: On modern Apple Silicon Macs (M1, M2, M3) and Intel Macs with the T2 Security Chip, the drive is actually already encrypted by default. However, the decryption key is tied to the hardware. Enabling FileVault ties the decryption key to your specific user password, providing the necessary protection against physical theft.

Step 1: Enable FileVault

  1. Open System Settings (or System Preferences on older OS versions).
  2. Navigate to Privacy & Security.
  3. Scroll down to the FileVault section.
  4. Click the Turn On… button. (You will be prompted to enter your administrator password).

Step 2: Choose a Recovery Method (Crucial Step)

If you forget your Mac login password, you will permanently lose access to all your data. Apple cannot recover it for you. FileVault forces you to create a backup Recovery Key.

You will be presented with two options:

  1. Allow my iCloud account to unlock my disk: This is the most convenient option for average users. If you forget your Mac password, you can use your Apple ID and password to reset it.
  2. Create a recovery key and do not use my iCloud account: This generates a random 24-character alphanumeric code (e.g., ABCD-1234-EFGH-5678-IJKL-9012). You must write this code down on a piece of paper and store it in a physical safe. If you choose this option and lose the paper, your data is gone forever. This option is preferred for highly sensitive corporate or legal environments.

Step 3: The Encryption Process

Once you make your selection, the encryption process begins.

  • On older Intel Macs with mechanical hard drives, the system must read and encrypt every single byte on the disk. This can take several hours, but it happens silently in the background. You can continue to use the Mac normally, and you can even shut it down (it will resume encrypting when you turn it back on).
  • On modern Macs with a T2 chip or Apple Silicon, the process is instantaneous because the drive is already hardware-encrypted; macOS simply wraps the existing hardware key with your user password.

Step 4: The Boot Process Change

Once FileVault is enabled, you will notice a change when you turn on your Mac.

Normally, a Mac boots up, loads the operating system, and then asks for your password. With FileVault, the Mac cannot load the operating system because it is encrypted. Therefore, it presents a pre-boot login screen immediately. You must enter your password to unlock the disk, and then the Mac proceeds to boot macOS.

Step 5: How to Disable FileVault

If you are selling your Mac and need to wipe it, or if you simply don’t want encryption anymore, you can turn it off.

  1. Go back to System Settings > Privacy & Security > FileVault.
  2. Click Turn Off…
  3. The Mac will begin decrypting the drive in the background. Do not attempt to wipe or format the drive until the decryption process reaches 100%.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.