{"id":2403,"date":"2020-12-02T22:00:49","date_gmt":"2020-12-02T21:00:49","guid":{"rendered":"https:\/\/azuregeek.io\/?p=2403"},"modified":"2021-01-22T00:30:43","modified_gmt":"2021-01-21T23:30:43","slug":"intune-macos-filevault-recovery-key-missing","status":"publish","type":"post","link":"https:\/\/azuregeek.io\/en\/intune-macos-filevault-recovery-key-missing\/","title":{"rendered":"Intune: macOS FileVault Recovery Key missing"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"2403\" class=\"elementor elementor-2403\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-2b65d21 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"2b65d21\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-a658750\" data-id=\"a658750\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5a63e1a elementor-drop-cap-yes elementor-drop-cap-view-default elementor-widget elementor-widget-text-editor\" data-id=\"5a63e1a\" data-element_type=\"widget\" data-settings=\"{&quot;drop_cap&quot;:&quot;yes&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>If you are mainly concerned with security, you will quickly come into contact with the topic of device management. Microsoft Endpoint Manager (formerly Intune) is a cloud-based management solution with which macOS-based devices can be managed.<\/p>\n<p>One of the first and most common tasks when implementing Device Management is to enable disk encryption - <i>for macOS FileVault<\/i> - by means of policy. The next time you restart your mac system, FileVault will automatically activate and the recovery key will be saved in Microsoft Endpoint Manager \/ Intune. This process is also called <i>FileVault Recovery Key Escrow<\/i> called. The FileVault Recovery Key can then be retrieved via the device profile in Microsoft Endpoint Manager \/ Intune.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-808567b elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"808567b\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-ec60c61\" data-id=\"ec60c61\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-02b3740 elementor-widget elementor-widget-image\" data-id=\"02b3740\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"480\" src=\"https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/12\/macbook-45x21.png\" class=\"attachment-large size-large wp-image-2557 lazy\" alt=\"\" data-srcset=\"https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/12\/macbook-1024x480.png 1024w, https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/12\/macbook-300x141.png 300w, https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/12\/macbook-768x360.png 768w, https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/12\/macbook-16x8.png 16w, https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/12\/macbook-45x21.png 45w, https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/12\/macbook.png 1482w\" data-sizes=\"100vw\" data-width=\"1024\" data-height=\"480\" data-src=\"https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/12\/macbook-1024x480.png\" srcset=\"https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/12\/macbook-45x21.png 45w, https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/12\/macbook-300x141.png 300w, https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/12\/macbook-1024x480.png 1024w, https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/12\/macbook-768x360.png 768w, https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/12\/macbook-16x8.png 16w, https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/12\/macbook.png 1482w\" sizes=\"(min-width: 960px) 75vw, 100vw\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-b726d93 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"b726d93\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-83defd0\" data-id=\"83defd0\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-81ce824 elementor-widget elementor-widget-text-editor\" data-id=\"81ce824\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>If FileVault was already active on the macOS device, the recovery key is not displayed. The reason for this is that the recovery key is only deposited with the escrow provider during a rotation. However, applying the FileVault policy will not trigger a rotation.\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4f7a497 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4f7a497\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-18718cf\" data-id=\"18718cf\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-29431ef elementor-widget elementor-widget-image\" data-id=\"29431ef\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"1024\" height=\"528\" src=\"https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/11\/2020-11-23_22h21_50.png\" class=\"attachment-large size-large wp-image-2404 lazy\" alt=\"\" data-srcset=\"https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/11\/2020-11-23_22h21_50-1024x528.png 1024w, https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/11\/2020-11-23_22h21_50-300x155.png 300w, https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/11\/2020-11-23_22h21_50-768x396.png 768w, https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/11\/2020-11-23_22h21_50.png 1533w\" data-sizes=\"100vw\" data-width=\"1024\" data-height=\"528\" data-src=\"https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/11\/2020-11-23_22h21_50-1024x528.png\" srcset=\"https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/11\/2020-11-23_22h21_50.png 1533w, https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/11\/2020-11-23_22h21_50-300x155.png 300w, https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/11\/2020-11-23_22h21_50-1024x528.png 1024w, https:\/\/azuregeek.io\/wp-content\/uploads\/2020\/11\/2020-11-23_22h21_50-768x396.png 768w\" sizes=\"(min-width: 960px) 75vw, 100vw\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-a017460 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"a017460\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-e85674a\" data-id=\"e85674a\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-8ece258 elementor-widget elementor-widget-text-editor\" data-id=\"8ece258\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>So we have the option of waiting for the next rotation to occur (configured in the FileVault policy) or we can do it ourselves. In the Endpoint Manager, however, the rotation can only be initiated manually if a recovery key is stored. If it is not, we must perform the rotation on the macOS device itself.\u00a0<\/p>\n<p>With these steps you solve the problem:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-a7da6cc elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"a7da6cc\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-33 elementor-top-column elementor-element elementor-element-e6ae61c\" data-id=\"e6ae61c\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-705a2dc elementor-view-default elementor-widget elementor-widget-icon\" data-id=\"705a2dc\" data-element_type=\"widget\" data-widget_type=\"icon.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon-wrapper\">\n\t\t\t<div class=\"elementor-icon\">\n\t\t\t<i aria-hidden=\"true\" class=\"far fa-lightbulb\"><\/i>\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-66 elementor-top-column elementor-element elementor-element-7458ac6\" data-id=\"7458ac6\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e0efcfd elementor-widget elementor-widget-text-editor\" data-id=\"e0efcfd\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ol><li>Open the terminal with a user who has administrator privileges<\/li><li>Execute the following command:<br \/><blockquote><em>sudo fdesetup changerecovery -personal<\/em><\/blockquote><\/li><li>Enter the password of the currently logged in user<\/li><li>Enter the user name of the currently logged in user<\/li><li>Re-enter the password of the currently logged in user<\/li><li>The new FileVault Recovery Key is displayed and automatically saved in Endpoint Manager<\/li><\/ol>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-9ac3d96 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"9ac3d96\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-888533e\" data-id=\"888533e\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-9da0ff1 elementor-widget elementor-widget-text-editor\" data-id=\"9da0ff1\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\tI hope this blog post has been helpful to you and I look forward to your comment! Sign up for my newsletter on the right to not miss any new posts about Azure Security and Automation \ud83d\ude00\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>You are using Microsoft Endpoint Manager (formerly Intune) for device management of macOS devices and you don't see a FileVault recovery key? In this post I'll show you how to make the recovery \"visible\" in Intune!<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[28],"tags":[],"_links":{"self":[{"href":"https:\/\/azuregeek.io\/en\/wp-json\/wp\/v2\/posts\/2403"}],"collection":[{"href":"https:\/\/azuregeek.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/azuregeek.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/azuregeek.io\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/azuregeek.io\/en\/wp-json\/wp\/v2\/comments?post=2403"}],"version-history":[{"count":50,"href":"https:\/\/azuregeek.io\/en\/wp-json\/wp\/v2\/posts\/2403\/revisions"}],"predecessor-version":[{"id":2684,"href":"https:\/\/azuregeek.io\/en\/wp-json\/wp\/v2\/posts\/2403\/revisions\/2684"}],"wp:attachment":[{"href":"https:\/\/azuregeek.io\/en\/wp-json\/wp\/v2\/media?parent=2403"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/azuregeek.io\/en\/wp-json\/wp\/v2\/categories?post=2403"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/azuregeek.io\/en\/wp-json\/wp\/v2\/tags?post=2403"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}