JAMF Pro FileVault Key re-escro
- rob32324
- Apr 29, 2022
- 6 min read
Updated: Sep 23, 2024
Don't let your users get locked out.

Disclaimer: think this through, read the solution. In this blog I am sharing a solution with fellow IT pros. I am offering insight into what I did to solve this issue for my own clients when I have encountered it, I am not telling you to do the same. iLogix Computer Solutions are not accountable for any issues introduced.
Scenario: You have FileVault enabled on your Macs through JAMF Pro with our Recovery Key Escrowed to JAMF Pro. This means you can help a user should they forget their Mac password and are unable to unlock their FileVault enabled Mac. FileVault will ensure that if the Mac is lost or stolen the users data will not be compromised.
We have created policies and profiles to force FileVault on our Macs in JAMF Pro.


However in JAMF Pro the inventory for some computers shows the following under inventory / Disk Encryption:

Where is the recovery key? this is serious as it could result in dataloss.
Solution: Create a bash script in JAMF Pro. Read through the script here and make any changes you need. It should not need much if any editing.
We add our script here.

Create a smart computer group in JAMF Pro to target any computer that does not have its recovery key available in JAMF Pro.

Create a policy scoped to this Smart Group and add the bash script to it. Publish it in Self Service.
Ask your users to run this script.
Next time we check our inventory we will be able to reveal the FileVault Recovery Key.

iLogix Computer Solutions are Apple and JAMF Certified. We support more than just your Mac hardware. Call us for more information and of course call us for help.
Mac support Basingstoke - Mac support Guildford - Mac support Farnborough
Mac support Reading - Mac support Camberley - Mac support Yateley
iLogix Computer Solutions - 01252 962898



