FileVault recovery keys after MDM re-enrollment
When a Mac re-enrolls in Oneleet MDM, Oneleet requests fresh FileVault key escrow when its effective device policy enables FileVault. Re-enrollment alone doesn’t establish whether the disk was erased or its recovery key changed.
Oneleet retains the previously saved encrypted key while waiting for fresh escrow. During this period, admins can reveal the saved key from Encryption key on the device page. It is labeled Saved before re-enrollment; not yet reconfirmed until Oneleet receives and stores a key again.
If the key remains unconfirmed, contact Oneleet support to investigate enrollment and escrow activity. An encrypted device can still be waiting for key escrow; FileVault being enabled doesn’t by itself confirm that Oneleet has received its current key.
Check whether the recovery key was saved
Section titled “Check whether the recovery key was saved”Open the device’s Activity tab and filter for FileVault recovery key saved or FileVault recovery key couldn’t be saved. A successful device-management response only confirms that the Mac answered the request. The separate recovery-key event confirms whether Oneleet saved the key.
If saving fails, the event details include the affected step and the related device-management request. Oneleet continues its scheduled key requests while the device remains enrolled and its retry budget allows. Keep the Mac online and contact Oneleet support if failures continue. Activity events never include the recovery key.