Mar 10 2017 01:57 AM
Hi all,
Is there a possibility to encrypt the disk (FileVault) of an Mac OS X device by using Intune? I read something about Apple Configurator, to create a profile and deploy it with Intune. But I cannot find information on how to setup such a profile for disk encryption. Anybody have a good article about this? Or another good solution to encrypt a harddisk on a Mac?
Thanks!
Peter
Mar 10 2017 02:10 AM
This look like somewhere to start https://www.johnkitzmiller.com/blog/how-i-deploy-filevault-2/
Some offical apple documentation http://training.apple.com/pdf/WP_FileVault2.pdf
Haven't done it myself so no experience.
Mar 13 2017 06:40 AM - edited Mar 13 2017 07:16 AM
Thanks! But this guy is using Casper, I`m looking for a solution based on intune (if possible).
Jun 03 2019 09:23 PM - edited Jun 03 2019 09:27 PM
Solution@Peter Klapwijk This feature is currently in development and is expected to be released this year.
https://www.microsoft.com/en-au/microsoft-365/roadmap?filters=&searchterms=51243
Till such time you can use the mac device compliance policy and set the "Encryption of data storage on a device to require". This will prevent users from storing company data on their device unless it is encrypted.
Jun 15 2019 12:02 AM
@Pramiti Bhatnagar Ok! Better late than never 😉
Jul 21 2019 04:17 PM - edited Jul 21 2019 04:17 PM
Jul 22 2019 04:19 AM
Jul 23 2019 06:22 AM
@Oliver Kieselbach do you know what will happen if I already have custom profile deployed to enforce Filevault?
Jul 23 2019 06:27 AM
honestly I don't know. I guess it could potentially conflict but don't know. I think you need to do some tests in a lab environment...
✌ best,
Oliver
Jun 03 2019 09:23 PM - edited Jun 03 2019 09:27 PM
Solution@Peter Klapwijk This feature is currently in development and is expected to be released this year.
https://www.microsoft.com/en-au/microsoft-365/roadmap?filters=&searchterms=51243
Till such time you can use the mac device compliance policy and set the "Encryption of data storage on a device to require". This will prevent users from storing company data on their device unless it is encrypted.