Are new systems encrypted?

I presume new computers purchased from Apple come with Mojave preinstalled. I’m wondering if these systems come with encryption turned on by default for the system drive.


Thanks very much.

Posted on Jan 19, 2019 5:13 AM

Reply
Question marked as Top-ranking reply

Posted on Jan 19, 2019 5:40 AM

FileVault is not just encryption.

FileVault also adds the magic that allows certain users to decrypt the drive and immediately log in to their account.

First iterations of FileVault2 required certain designated users to decrypt the drive before anyone could log in. Now, those users are immediately logged into their accounts when they "log in" on the FileVault decryption login window.


The T2 chip encrypts the drive on those Macs, regardless of FileVault.

If you enable FileVault on one of them, you get the Login/Decrypt feature of FileVault, but the drive remains encrypted by the T2 chip.


So, FileVault is not enabled on T2 Macs, but the drive is encrypted.

If you want to control the decryption process with a user login password, you would need to enable FileVault.

The drive is not encrypted by FileVault, the login/decrypt function is tied to the decryption key on the T2 chip.

7 replies
Question marked as Top-ranking reply

Jan 19, 2019 5:40 AM in response to Tom Wolsky

FileVault is not just encryption.

FileVault also adds the magic that allows certain users to decrypt the drive and immediately log in to their account.

First iterations of FileVault2 required certain designated users to decrypt the drive before anyone could log in. Now, those users are immediately logged into their accounts when they "log in" on the FileVault decryption login window.


The T2 chip encrypts the drive on those Macs, regardless of FileVault.

If you enable FileVault on one of them, you get the Login/Decrypt feature of FileVault, but the drive remains encrypted by the T2 chip.


So, FileVault is not enabled on T2 Macs, but the drive is encrypted.

If you want to control the decryption process with a user login password, you would need to enable FileVault.

The drive is not encrypted by FileVault, the login/decrypt function is tied to the decryption key on the T2 chip.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Are new systems encrypted?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.