Skip to content

FileVault recovery keys after MDM re-enrollment

When a Mac re-enrolls in Oneleet MDM, Oneleet requests fresh FileVault key escrow when its effective device policy enables FileVault. Re-enrollment alone doesn’t establish whether the disk was erased or its recovery key changed.

Oneleet retains the previously saved encrypted key while waiting for fresh escrow. During this period, admins can reveal the saved key from Encryption key on the device page. It is labeled Saved before re-enrollment; not yet reconfirmed until Oneleet receives and stores a key again.

If the key remains unconfirmed, contact Oneleet support to investigate enrollment and escrow activity. An encrypted device can still be waiting for key escrow; FileVault being enabled doesn’t by itself confirm that Oneleet has received its current key.

Open the device’s Activity tab and filter for FileVault recovery key saved or FileVault recovery key couldn’t be saved. A successful device-management response only confirms that the Mac answered the request. The separate recovery-key event confirms whether Oneleet saved the key.

If saving fails, the event details include the affected step and the related device-management request. Oneleet continues its scheduled key requests while the device remains enrolled and its retry budget allows. Keep the Mac online and contact Oneleet support if failures continue. Activity events never include the recovery key.