FileVault Mac OS not being enabled

Michael Novak 81 Reputation points
2021-04-27T07:13:47.88+00:00

Hello all,

I have a really hard time understanding differences between "Endpoint Security > Disk Encryption" pane in Endpoint Manager and Devices > Configuration profiles. In both these locations, there is the same MacOS FileVault encryption policy I can configure. Can someone explain the difference ?

The issue:

I am trying to enable FileVault encryption for Mac OS for one particular user (E3 license) and when I configure the policy in the 1st location, assign it to a security group, the policy is not getting applied at all. I Company portal app is in sync, and I can see the device in Devices with Encryption status of:

Device encryption status

Device name
<User's> MacBook Air
Encryption readiness
Not ready
Encryption status
Not encrypted
Profiles

  • <Our company> MacOS policy
  • <Our company> - a7f54769-67b4-49ce-8100-3ee5ab26bdad_72AE5DD3-237F-4854-8B50-358A310B9565 (this is the Windows 10 policy being applied to the group as well as there are other W10 users in this group )
    Profile state summary
    Pending
    Status details
    Unknown
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,742 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,265 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Lu Dai-MSFT 28,356 Reputation points
    2021-04-27T09:13:00.94+00:00

    @Michael Novak Thanks for posting in our Q&A.

    For FileVault settings in different locations, they are the same configuartion.

    For this issue, I have done a lot of research. This is may caused by the device has already enable FileVault before enrolling to Intune receive FileVault policy. Did you enable FileVault before? If not, it is needed to do log analysis to find the root cause.

    With Q&A limitation, Q&A is not the best channel for such log analysis case. So we suggest to open a case to check on this. It is free. The following link describes how to open a case, we can refer to it:
    https://learn.microsoft.com/en-us/mem/intune/fundamentals/get-support

    Hope this issue will be solved as soon as possible.


    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Michael Novak 81 Reputation points
    2021-04-27T09:40:09.427+00:00

    Hello, many thanks for your answer. You're correct, it has not been enabled before, as this is a new computer, which has been just recently setup. Company portal app is enabled and synced, I can also see the computer in Intune (endpoint manager) portal with no errors.

    The only information I can find is in Home > Devices > Monitor > Encryption report where the device is showing "Encryption Readiness: Not ready". The device is MacBook Air with M1 chip (2020).


  3. Ott Alexander 1 Reputation point
    2021-10-26T14:12:14.96+00:00

    Hi Michael,

    that's interesting, I get the same error message on my M1 Macbook Air. Did you manage to activate filevault in the meantime?

    0 comments No comments