FileVault on a Mac: what it locks and what it leaves alone
Searching for FileVault returns two kinds of page. One is a two step instruction to open Privacy and Security and flip a switch. The other is a fleet deployment guide about bootstrap tokens and escrow. Neither answers the question that sent most people looking, which is what changes on the Mac after the switch is on, and whether anything is left unprotected afterwards.
The honest version has a surprise in it. On any Mac sold in the last several years the disk is already encrypted before FileVault is touched, so the switch is not doing what its name suggests.
The disk is already encrypted before the switch is on
Apple states this at the top of both pages that explain the feature.
If you have a Mac with Apple silicon or an Apple T2 Security Chip, your data is encrypted automatically. Turning on FileVault provides an extra layer of security by keeping someone from decrypting or getting access to your data without entering your login password. Source: support.apple.com, read September 28, 2026
The security documentation explains what the difference consists of. Every APFS volume is created with a volume encryption key, and that key is itself wrapped by a key encryption key. With FileVault off on an Apple silicon or T2 Mac, the wrapping key is protected only by the hardware identifier held in the Secure Enclave. With FileVault on, it is protected by a combination of the login password and that hardware identifier.
That is the whole mechanism, and it explains two things that otherwise look odd. Turning FileVault on is immediate rather than an hours long encryption pass, because the data is already encrypted and only the key wrapping changes. And an anti replay mechanism prevents the old hardware only key from being used afterwards, so the switch is not reversible by recovering a previous key.
The exception matters for anyone on older hardware. On a Mac from before the T2 chip, on internal storage that did not ship with the Mac, and on attached external storage, FileVault performs a real encryption pass, and only files present at the time plus everything written afterwards are covered.
What it locks
The protection is specific: data at rest on internal storage, against someone who has the machine or the chip out of it.
Without valid login credentials or a cryptographic recovery key, the internal APFS volumes remain encrypted and are protected from unauthorized access even if the physical storage device is removed and connected to another computer. Source: support.apple.com, read September 28, 2026
Apple describes the key hierarchy as designed to achieve four things at once: requiring the password for decryption, resisting a brute force attack mounted directly against storage removed from the Mac, allowing content to be wiped quickly by destroying key material, and allowing a password change without re encrypting the volume. The last of those is why changing a login password on a FileVault Mac takes seconds.
On Apple silicon and T2 Macs, all FileVault key handling happens inside the Secure Enclave and the encryption keys are never directly exposed to the main processor. From macOS 11 onwards the system volume is protected separately by the signed system volume feature, and FileVault's job is the data volume, which is where everything that belongs to a person actually lives.
What it leaves alone
This is the part the ranking pages skip, and it is where the real decisions are.
| Not covered | Why |
|---|---|
| A Mac that is logged in | The volume is unlocked while in use, so anything running has normal access |
| External and removable drives | Encryption there does not use the Secure Enclave and is a separate setting per disk |
| Time Machine backups | The backup disk has its own encryption option, chosen when the disk is set up |
| Data deleted before FileVault was turned on | It was never encrypted, and may be recoverable |
| Anything reachable over the network | A firewall and an unlocked screen are different problems |
The deletion point is worth stating in Apple's words, because it is the one that surprises people who turn FileVault on years into owning a Mac.
After FileVault is turned on, all existing files and any further data written are encrypted. Data that was added and then deleted before turning on FileVault isn't encrypted and may be recoverable with forensic data recovery tools. Source: support.apple.com, read September 28, 2026
On an Apple silicon or T2 Mac that applies to an older and narrower window than it sounds, since the volume was encrypted from the start under the hardware key. On an Intel Mac without the T2 chip it is a real gap, and the only clean remedy is to erase and start over rather than to enable FileVault on a disk with years of history behind it.
The external drive case is the most common practical miss. FileVault applies to the startup disk. A backup drive, a scratch disk full of video, and a USB stick carrying the same documents are all separate decisions, and Apple notes plainly that encryption of removable storage does not use the Secure Enclave's capabilities and behaves as it would on an Intel Mac without a T2 chip.
The recovery key is the only part that can end badly
The switch itself is safe. The choice made during setup is not, and Apple's warning about it is unusually blunt.
WARNING: Don't forget your recovery key. If you turn on FileVault and then forget your login password and can't reset it, and you also forget your recovery key, you won't be able to log in, and your files and settings will be lost forever. Source: support.apple.com, read September 28, 2026
There are two options at that point. Allowing an iCloud account to unlock the disk avoids keeping track of anything separate. Creating a recovery key produces a sequence of 24 random numbers and letters instead.
Several facts about that key are documented and rarely mentioned. It can be viewed afterwards in System Settings under Privacy and Security, then FileVault. It is stored in the keychain, which means it can be retrieved through the Passwords app. With iCloud Keychain in use it is synchronised along with other passwords. And at the login window it is entered by pressing Shift, Option and Return instead of typing a password, which is the part nobody remembers at the moment it is needed.
Writing it down remains sensible, and Apple's instruction about where is specific: not on the encrypted disk, and not in the same physical place as the Mac.
Extra users, and one remote unlock worth knowing
On a Mac with more than one account, FileVault is granted per user. Any account with FileVault turned on can start the Mac and log in. An account without it cannot start the Mac at all, and Apple describes the workaround exactly: another user who does have it must start up, log in, and then log out without restarting, after which the other account can log in. The Enable Users button in FileVault settings is where each account's login password is entered to grant it.
For a Mac that is not physically present at restart time, there is now a way out of the boot password requirement. Apple's deployment documentation states that on a Mac with Apple silicon running macOS 26 or later, FileVault can be unlocked over ssh after a restart when Remote Login is turned on and a network connection is available. That single line removes the main reason server style Macs used to be left with FileVault off.
Why erasing a FileVault Mac takes seconds
The same key hierarchy explains a behaviour most people meet without understanding it. Erasing a modern Mac completes in moments rather than in the hours a full overwrite would need, and the reason is that nothing is overwritten.
Apple describes the mechanism in terms of a single additional key. All volume encryption keys are wrapped with a media key, which adds no confidentiality of its own and exists only so that data can be destroyed quickly. Deleting it makes decryption impossible, and on an Apple silicon or T2 Mac the Secure Enclave guarantees that the media key can be erased, including in response to a remote device management command. Erasing it, in Apple's phrase, renders the volume cryptographically inaccessible.
Two consequences follow. Selling or handing on a Mac does not require a wiping utility, because the erase already destroys the only thing that made the data readable. And a stolen managed Mac can be made unreadable remotely without any need to reach the disk itself.
The same documentation notes that when a volume is deleted, its volume encryption key is securely deleted by the Secure Enclave so that even the Secure Enclave cannot use it again. That is worth knowing before deleting an APFS volume in Disk Utility in the belief that the data could be recovered later. It cannot.
The switch this is often confused with
FileVault covers data at rest, and nothing else. It has no opinion about network traffic, which is the job of a different pane entirely: the firewall, which lives in System Settings under Network and controls incoming connections. Turning FileVault on does nothing about a Mac that is reachable on a hostile network, and turning the firewall on does nothing for a laptop left in a taxi.
The third piece is the lock screen. FileVault protects a Mac that is off or restarted, because that is when the login password is required to unlock the volume. A Mac that is awake and logged in has an unlocked volume by definition, so a short screen lock delay does more for everyday safety than any encryption setting.
The visible cost, day to day
Turning FileVault on turns on related requirements, and the one that is noticed is a password prompt when the Mac wakes from sleep or comes back from the screen saver. On a machine used in a private room that is friction with no benefit, and it is not optional.
What is worth noticing is how little FileVault shows about itself. There is no menu bar item, no indicator, and no status anywhere except the settings pane. The menu bar does carry security information, but a different kind: the orange, green and purple dots beside Control Center that report the microphone, camera and system audio being in use, and the arrow that reports location access. Those are genuine live indicators and are the one part of a crowded menu bar that should never end up hidden, which is worth checking before rearranging anything up there.
What to change first
Turn it on, choose the recovery key option rather than the iCloud one if the Mac ever leaves the house, and then confirm the key is retrievable in the Passwords app before closing the settings pane. After that, look at the drives FileVault does not cover, starting with the Time Machine disk, since an unencrypted backup of an encrypted Mac undoes most of the work. For the separate problem of a menu bar so full that the privacy indicators are the first thing pushed out of sight, Koffret is the tool for that.
Frequently asked questions
Does FileVault slow down a Mac?
On an Apple silicon or T2 Mac the data is already encrypted whether FileVault is on or off, and all key handling happens in the Secure Enclave rather than on the main processor, so there is no additional work to do. On older Intel Macs without the T2 chip the encryption is performed in software and there is a real, if usually small, cost.
Does FileVault protect my external hard drive?
No. FileVault covers the startup disk. Encryption on a removable drive is a separate choice made for that drive, and Apple notes it does not use the Secure Enclave's hardware protections the way internal storage does.
What happens if I forget both my password and my recovery key?
The data is unrecoverable. Apple states that files and settings are lost forever in that situation, which is why the recovery key is worth verifying rather than assuming. It can be viewed in System Settings under Privacy and Security, and it is stored in the keychain so the Passwords app can retrieve it.
Is turning FileVault off dangerous?
It removes the extra layer rather than decrypting everything on an Apple silicon or T2 Mac, where the volume stays encrypted under the hardware key alone. The practical effect is that the login password no longer stands between a removed drive and its contents, which is the whole reason to have it on.
Why does my Mac ask for a password after the screen saver now?
Because turning on FileVault turns on related security requirements, including a password prompt on waking from sleep or returning from the screen saver. It is part of the feature rather than a separate setting that drifted.