Hello,
Thanks for reaching out to Hexnode Connect.
If a FileVault Personal Recovery Key (PRK) was generated before a valid MDM escrow policy was in place, Hexnode cannot retrieve or decrypt the old recovery key by itself. Hexnode acts as a secure storage location only when the key is generated and escrowed directly through the active MDM workflow.
Fortunately, you do not need to decrypt and re-encrypt the entire disk. Instead, you just need to rotate the PRK locally to generate a fresh key for Hexnode to capture. You are also correct that an incomplete policy configuration (such as missing certificate settings) will prevent the recovery key escrow from succeeding.
Here is the exact workflow to correct your policy and escrow the keys for Macs that are already encrypted:
- Update the FileVault Policy: Ensure your Hexnode FileVault policy is fully configured (including the recovery key and certificate setup), save it, and ensure it is successfully assigned to the affected Macs.
- Rotate the Personal Recovery Key: On the already-encrypted Mac, run the following command in Terminal: sudo fdesetup changerecovery -personal. (Note: This command generates a new PRK but requires user or local admin credentials, meaning it cannot be fully automated through a silent script without user interaction).
- Scan the Device: After the Terminal command completes, trigger a Scan Device action from the Hexnode portal so the Mac checks in and the new recovery key is escrowed.
Once the Mac reports back successfully, the new key will appear in Hexnode on the device details page under Device Info > Security > FileVault Recovery Key.
(Note: Moving forward, for any new enrollments, enforcing FileVault through your newly corrected Hexnode policy will escrow the PRK automatically during the initial setup).
I hope this helps or resolves your issue. Feel free to reach out if you have any more doubts or need further assistance.
Best regards,
George,
Hexnode UEM