Cannot switch off File Vault using admin account - "Account cannot be used to manage encryption"

I have been trying to switch off File Vault, however, I get getting "Account “(account name)” cannot be used to manage encryption on this Mac. Click the lock to prevent further changes, then select another administrator account, and try again.

The account I am using is the initial and only admin account. I have tried with another admin account (which I managed to successfully create) however, I am still getting the same error.

Posted on Dec 14, 2017 12:44 AM

Reply
Question marked as Top-ranking reply

Posted on Dec 15, 2017 9:42 PM

I had this same, incredibly frustrating problem. Thankfully the solution that worked for me is very simple.


first, create a new user, make sure it's an admin user. give it a password. log out of your old user, log into your new user, and then reset the password of your old user. make sure you pick a different password than you have now.


be aware that keychain will still use your old password, so don't forget it just yet.


Log out of your new user, log into your old user. voila, that user now has the securetokenon flag set. you can now disable Filevault.


be aware than when you lock back into your old user, iCloud, keychain, and all your email accounts will require you to log back in. this is a security measure to prevent unwanted access to your secure iCloud contents. you will have to enter your iCloud/apple account password several times. this is normal behavior.


when keychain asks for your password, it will be the password your old user had before you reset it.

16 replies
Question marked as Top-ranking reply

Dec 15, 2017 9:42 PM in response to and10

I had this same, incredibly frustrating problem. Thankfully the solution that worked for me is very simple.


first, create a new user, make sure it's an admin user. give it a password. log out of your old user, log into your new user, and then reset the password of your old user. make sure you pick a different password than you have now.


be aware that keychain will still use your old password, so don't forget it just yet.


Log out of your new user, log into your old user. voila, that user now has the securetokenon flag set. you can now disable Filevault.


be aware than when you lock back into your old user, iCloud, keychain, and all your email accounts will require you to log back in. this is a security measure to prevent unwanted access to your secure iCloud contents. you will have to enter your iCloud/apple account password several times. this is normal behavior.


when keychain asks for your password, it will be the password your old user had before you reset it.

Feb 12, 2018 5:57 PM in response to Livingroom

I tried Livingroom's solution, but unfortunately it didn't work. The "cannot be used to manage encryption on this Mac" error message continues to appear.


I suspect that in my case, and perhaps many others', the problem originated with the fact that when I used a bootable High Sierra installer to format a new SSD so that I could install High Sierra onto it, I formatted it as "APFS (Encrypted)" rather than simply "APFS". That means the newly-created APFS volume was encrypted in a context where users that would exist on the new volume hadn't been created yet. I expect that if I had formatted the SSD without encryption, then installed the OS, then booted from the new drive, and only *then* encrypted the volume by turning on FileVault, I would not be having this issue. (The real problem I'm trying to solve is that when booting from the new volume, it's no longer possible get to the user login screen without *first* having to separately type in the "Disk Password", as opposed to my user login automatically unlocking the disk without requiring me to type two different passwords.)


I'm not entirely sure whether to think of this situation as a "bug" in High Sierra, or the unanticipated but predictable result of encrypting an intended APFS boot volume from within a user session that was booted from a *different* volume. I hope that Apple, or some clever expert, comes forward with a solution that doesn't require reformatting the targeted drive *without* encryption and then either restoring from backup or starting over.

Dec 16, 2017 1:16 PM in response to Livingroom

Thank you very much for potential solution. I didn’t get a chance to try it out because I decided to proceed with a disk erase and a réinstallation of the OS with a restore from time machine. I set the newly formatted drive as non encrypted and my backup had no encryption anyway. As a result my primary drive has no filevault enabled anymore; however, I am not sure if I‘ll get any problems should I decide to enable it.

Feb 14, 2018 1:51 PM in response to plochner

I believe the answer is no, there is no difference in the resulting drive security. The only functional difference appears to be that if you're going to be booting macOS from the drive in question, you will only be able to integrate the disk password into your user login if you set up the encryption via FileVault. If you apply encryption at the time the disk is formatted, this won't be possible, meaning you'll be forced to enter the disk password separately during the boot process, before you reach the user-login screen.


For evidence, I would call your attention to the way that the output of the "diskutil apfs list" command is formatted. The fifth line of information printed beneath each APFS Volume indicates whether the volume is encrypted, and if so, whether it's presently unlocked (i.e. the necessary credentials have been supplied so that the encrypted content of the volume is accessible). The *label* at the left end of that line is not "Encypted:" or "Encryption:" — it's "FileVault:". This is true regardless of whether the encryption was applied at formatting, or later using the FileVault prefpane. Provided that the underlying filesystem is indeed APFS, there is no difference in the encryption itself!

Jan 29, 2018 2:31 PM in response to JordanBueno

Ran into this problem this morning too. Brand new mac, straight out of the box from the Apple Store, bought a week ago.


Just trying to turn on Filevault. I created an Admin user (let's call it CompanyAdmin) and then logged that user out. Then I created another user (Susie) and made her Admin. While logged in as Susie I can't enable file vault.


When I log back in with CompanyAdmin, I can turn it on file. Just can't do it when I'm logged in with Susie. Functionally, it's the same because when I'm logged in as CompanyAdmin and setting up FileVault, I have the option to check a box on Susie's name and enable her so she can log in with her own username and password to unlock the account.


Appears to be yet another bug in High Sierra. I have set up hundreds of computers with Filevault and you were always able to turn it on with a second Admin account.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Cannot switch off File Vault using admin account - "Account cannot be used to manage encryption"

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.