multi-users shared computer - APFS encryption ? or filevault for each user ?

Hello,


I will need to setup my 2015mba (512gb ssd and 8gb ram) as a multi-users-machine : for myself through an administrator account and for my kids through another account but non-admin for this last one .


As the mba is 11" (no sdcard slot...) and will go outside I wish to encrypt the data it will store . So, if it is stolen or lost : extracting the ssd will NOT allow access to the data stored on it, for anybody) . Allright .


From that : what encryption type should I choose ?

As the need is : I prefer my kids won't need any other password to type than the one they will use to login into their account, in order to both login and decrypt ... (Am I clear ?)


Apparently filevault is a good way for that purpose .


But my question is : can I get this beahviour with a partition-level-apfs-encryption, too ?

As I will make a fresh install for this machine, I will format the drive as apfs (is hfs by now...) . And I saw there is an option when formatting through the MacOS-installer-utility-disk-tool that allows to encrypt directly the partition...


I'm now a bit confused about the path to choose ...

Filevault for each user ?

Or general apfs-encryption for the whole drive ?


Any help or suggestion ?


Note : The destination OS will probably be BigSur as he is really thrifty in ram usage . My experience shows it only "eats" around 1,7GB after startup (while Monterey needs around twice of that...) . And as it will quite often happen the computer runs two simultaneous sessions (Mine and kids), ram usage is a parameter I won't/can't really neglect . All apps we will run are compatible with BigSur, so it's not a so bad compromise (-: ...


Thanks :-) .

MacBook Air 13″, macOS 14.7

Posted on Jan 25, 2025 7:45 AM

Reply
Question marked as Top-ranking reply

Posted on Jan 25, 2025 10:21 PM

Just erase the whole physical SSD (Intel Macs only) as GUID partition and APFS (top option). You need to click "View" within Disk Utility and select "Show All Devices" before the physical SSD appears on the left pane of Disk Utility.


Then install macOS.


Once macOS is installed & configured, then enable FileVault so that you can be given a Filevault Recovery Key to use to unlock the volume if the password is forgotten or doesn't work for some reason. This will allow each user to unlock the system when logging into their individual user accounts.

Encrypt Mac data with FileVault - Apple Support


Similar questions

2 replies
Question marked as Top-ranking reply

Jan 25, 2025 10:21 PM in response to EulGui

Just erase the whole physical SSD (Intel Macs only) as GUID partition and APFS (top option). You need to click "View" within Disk Utility and select "Show All Devices" before the physical SSD appears on the left pane of Disk Utility.


Then install macOS.


Once macOS is installed & configured, then enable FileVault so that you can be given a Filevault Recovery Key to use to unlock the volume if the password is forgotten or doesn't work for some reason. This will allow each user to unlock the system when logging into their individual user accounts.

Encrypt Mac data with FileVault - Apple Support


Jan 27, 2025 12:56 AM in response to HWTech

Hello .


Thanks for the help .


But I did the stuff meanwhile 🙃


I choosed to encrypt the whole apfs partition directly during install process (disk utility, then erase all existing partitions, then create an new apfs-encrypted one) .  Worked as intended : disk utility asked me to setup a password (si did I) before he can proceed the partitioning . From that I launched the install, which provided me a recovery key (I wrote somewhere of course…) at some time . After the install succeeded (by creating the admin account) I created the non-admin-users . They directly inherit from admin-account the abilty to decrypt the drive through their user-account-password, so the encryption is totaly transparent for them .


The difference with a non-encrypted OS, for the users, is : their account password is asked from the start of the boot (by the bootloader I guess), only after that : the bootloader starts the OS (progress bar) . On a non-encrypted install this is quite the opposite : the OS loads its stuff first (the progress bar), then he asks the user-account-password only when he is ready to show up the desktop .


I noticed the OS is slower to start (the time the partition gets decrypted I think…), it’s not critical but visible .


Job done :-) .

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

multi-users shared computer - APFS encryption ? or filevault for each user ?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.