Safeguard Authentication Services is compatible with Apple’s FileVault disk encryption, introduced in macOS 10.7. To use FileVault with an Active Directory user, you must first create a mobile account for that user on the macOS client. A macOS mobile account has a local home directory that can automatically sync with the user’s network home directory.
To encrypt your disk
-
As an Active Directory user, open System Preferences and navigate to Users & Groups.
-
Click the Lock icon and enter administrator credentials to enable preference changes.
-
Click the Create button next to Mobile account.
-
Select your preferred syncing and home folder location preferences in the pop-up menu and click Create.
A popup message displays explaining that you must log out and log back in to create the local home folder.
-
Click Create and enter your password at the prompt.
-
Log back in and configure FileVault encryption.
-
From System Preferences, navigate to Security & Privacy and open the FileVault tab.
-
Click Turn on FileVault to begin the encryption process.
-
Select users (local users and mobile accounts) to enable them to unlock the encrypted disk at system startup.
NOTE: Once you enable FileVault unlock for a user account, if you subsequently delete the account from Active Directory, you must also delete the local user account to disable FileVault unlock for that user.
-
Enter a password for each user you enable.
-
Take note of the recovery key on the following screen; store it somewhere yourself, and store it with Apple Support.
-
Restart your system to begin encrypting the drive.
The encryption can take several hours, depending on the size of your disk, during which time you can continue using your computer. You can monitor the encryption process by returning to the FileVault tab in Security & Privacy preferences.
After you enable FileVault, your macOS will initially boot to an unencrypted disk partition and ask for your password to unlock the encrypted partition. Because this separate partition does not have access to Safeguard Authentication Services and Active Directory, you must use your most recent locally cached password. Before the local cache is updated, if you need to unlock the encrypted disk after a password change, either use your old password or click the Recover Key to unlock the drive. Once the drive is unlocked, although it says you must reset your password, you can ignore the prompt and log in with your recently changed account password.