Installing the Encryption Management for Apple FileVault Agent
To install Encryption Management for Apple FileVault, perform the following procedure.
- Verify that all of the agent installation prerequisites have been completed.
-
Verify that the hard disk is not already encrypted, no other full disk
encryption product is installed, and that Apple FileVault is disabled.
- Go to System Preferences > Security & Privacy.
-
Select the FileVault tab.
- If necessary, click the lock icon () to make changes.
- Specify the user name and password for the endpoint.
- Click Turn Off FileVault.
-
Run a hard drive integrity utility on the system
drive.
For example, run Verify Disk from OS X Disk Utility. To use this feature, do the following:
- Restart your Mac in Recovery Mode by holding Command + R during startup.
- Click Disk Utility.
- Select your startup disk.
- Click Verify Disk.
- If errors are found on the disk, click Repair Disk.
- Check with your system administrator about whether you should defragment your system drive.
- Copy the installation files to the system drive.
- Run TMFDEInstall_FV.exe.
-
From the Welcome screen, click
Continue.
The Installer checks that the system requirements are met.
- If the system requirements are met, click Install.
- Select the hard disk to install that agent.
-
Specify the user name and password of an account with permission to install
applications on the endpoint, and click Install
Agent
The installation begins.
-
Specify the following PolicyServer information:
Option Description Server name
Specify the PolicyServer IP address, host name, or FQDN and include the port number assigned to that configuration.
Enterprise
Specify the Enterprise. Only one Enterprise is supported.
User name
Specify the user name of an account with permission to add devices to the Enterprise.
Password
Specify the password for the user name.
Important:Make sure that you type the correct password at this time, or you may need to troubleshoot your encryption status later.
-
After the installation completes, click Close to restart
the endpoint.
The Encryption Management for Apple FileVault agent initiates immediately after the endpoint restarts.
-
Go to the menu bar () to open the Encryption Management for Apple FileVault agent.
Note:
For information about understanding and managing the Endpoint Encryption agent, see the Endpoint Encryption Administrator's Guide.
Creating a Mobile Account for Active Directory on Mac OS
Mac OS local accounts or mobile accounts are able to initiate encryption on Mac OS X Mountain Lion or later. Other Mac OS user account types will be unable to initiate encryption.
If a Mac OS account other than a local account or mobile account attempts to initiate encryption, the following notification appears:
The following task shows how to create a mobile account for your Mac OS account to bypass this issue.
-
Go to System Preferences... in the Apple menu.
The System Preferences window appears.
- Select User Groups under the System section.
- Click the lock icon in the lower left corner.
- Click Create... next to Mobile account.
- On the following screens, select any personal settings, and click Create to proceed from one screen to the next.
-
When prompted, enter your Active Directory password and click
OK.
Your mobile account has been created. You may now use this mobile account to initate encryption.