Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

How to encrypt non-boot Volume so available at login?

Hi folks - I've been using FileVault for years quite successfully to encrypt my internal HD and like the simplicity and security it's provided.


I've upgraded my 2017 iMac's former HD/SSD Fusion drive, with a new 240GB blade SSD as the Mac boot volume with Admin account, and a second 1TB SATA SSD as my Data volume for my regular user account and home folder. Completely clean install of Big Sur and about to restore my data.


Where I'm now stuck ... is it still possible to encrypt the SATA SSD using FileVault or similar, such that drive contents are encrypted until login? It seems FileVault only supports the boot volume which is the blade only, and I tried creating an encrypted volume on the SATA but it does not automatically decrypt at login and login then fails. I've thought about refusing the 2 SSD's but understand I'm better to leave them separate from a performance and reliability pov.


Seems this would be a fairly common use case especially for the higher end machines with multiple physical storage drives.


Is there a simple way through this?


Thanks much

Posted on Nov 29, 2020 6:59 AM

Reply
Question marked as Best reply

Posted on Dec 1, 2020 7:09 AM

For the record books, here is where I landed.


After not being able to find a simple way to reenable FileVault or similar encryption on my Data Drive, I opted to refuse the 2 SSD’s per the simple steps here. Note there is a lot of outdated information elsewhere on refusing drives per older OS versions. As of BigSur and Nov 2020, these worked perfectly for me and took about 60 seconds to complete.


While there is a lot of discussion online why technically this may not yield absolute maximum drive performance, so far practically it has been plenty fast for my purposes and far simpler in terms of leaving things where Mac OS expects them (on the boot drive), thus allowing things like:

  • Simple reactivation of FileVault on the full volume
  • Full use of the combined 1.24TB of the 2 SSD’s
  • No monkeying around with advanced user settings to relocate the User Home folder.

Hope others find it useful.

djd

Similar questions

1 reply
Question marked as Best reply

Dec 1, 2020 7:09 AM in response to David Duran1

For the record books, here is where I landed.


After not being able to find a simple way to reenable FileVault or similar encryption on my Data Drive, I opted to refuse the 2 SSD’s per the simple steps here. Note there is a lot of outdated information elsewhere on refusing drives per older OS versions. As of BigSur and Nov 2020, these worked perfectly for me and took about 60 seconds to complete.


While there is a lot of discussion online why technically this may not yield absolute maximum drive performance, so far practically it has been plenty fast for my purposes and far simpler in terms of leaving things where Mac OS expects them (on the boot drive), thus allowing things like:

  • Simple reactivation of FileVault on the full volume
  • Full use of the combined 1.24TB of the 2 SSD’s
  • No monkeying around with advanced user settings to relocate the User Home folder.

Hope others find it useful.

djd

How to encrypt non-boot Volume so available at login?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.