macOS FileVault recovery key not showing in Hexnode after enabling escrowSolved

Participant
Discussion
2 days ago Jul 20, 2026

We enabled FileVault management in Hexnode because we want to recover Macs when users forget their passwords. On one Mac, FileVault is already enabled and the only local admin password is forgotten. The Reset Password action asks for administrator account credentials, which we don’t have.

The Mac is powered on and connected to the internet, but Hexnode shows the last check-in as about a day ago. Commands are staying pending. Also, after enabling Escrow Personal Recovery Key in the FileVault policy for some Macs that were already encrypted, the recovery key is not showing under Security Info.

What is the correct way to get the FileVault Personal Recovery Key escrowed in Hexnode? Can the Activation Lock bypass code help unlock the Mac?

Replies (3)

Marked SolutionPending Review
Hexnode Expert
1 day ago Jul 20, 2026
Marked SolutionPending Review

For macOS devices with FileVault enabled, there are a few separate points to consider.

1. The Reset Password remote action requires the credentials of an existing local administrator account on the Mac to authorize the password change. If the only local admin password is forgotten, that action cannot be completed using Hexnode alone.

2. If the Mac is sitting at the FileVault pre-boot login screen, it may appear to be online, but macOS has not fully loaded the management services yet. In this state, the device cannot check in with Hexnode, and remote actions such as creating a user, resetting a password, or pushing a new configuration will remain pending until the disk is unlocked locally.

3. An Activation Lock bypass code cannot be used to unlock FileVault or reset a macOS login password. It is only used for clearing Activation Lock after a device is erased or activation-locked.

If the Personal Recovery Key was already escrowed in Hexnode, you could retrieve it from the portal and use it at the FileVault login screen to unlock the Mac and reset the user password. The key can be viewed from:

Manage > select the Mac > Device Info > Security Info

To use the key on the Mac, enter the wrong password three times at the FileVault login screen. When macOS shows the option to reset using the Recovery Key, select it, enter the Personal Recovery Key, and then create a new login password.

If the recovery key was not escrowed before the password was forgotten and the Mac cannot check in, the password must be reset locally using macOS Recovery.

Regards,
Mary Romero

 

Marked SolutionPending Review
Participant
19 hours ago Jul 20, 2026
Marked SolutionPending Review

That explains why the commands are pending. But what about Macs that are already encrypted? I enabled the Escrow Personal Recovery Key option in the FileVault policy, but Hexnode still does not show the recovery key for those devices.

Marked SolutionPending Review
Hexnode Expert
17 hours ago Jul 20, 2026
Marked SolutionPending Review

If the FileVault policy with Escrow Personal Recovery Key enabled is applied after the Mac is already encrypted, Hexnode may not immediately have the existing Personal Recovery Key to escrow.

 

For already encrypted Macs, use one of these approaches:

 

Option 1: Disable and re-enable FileVault using the Hexnode policy

– Disable FileVault locally on the Mac.

– Reapply or repush the FileVault policy from Hexnode with Escrow Personal Recovery Key enabled.

– Once FileVault is enabled again through the policy and the Mac checks in, the Personal Recovery Key should be escrowed to Hexnode.

 

Option 2: Generate a new Personal Recovery Key on the Mac

If the Mac is accessible and you have administrator access, open Terminal and run:

macOS will generate a new Personal Recovery Key. After that:

1. Run Scan Device from Hexnode.

2. Open the device in Manage.

3. Go to Device Info > Security Info.

4. Use the Decrypt FileVault Recovery Key option if shown.

5. Select the applicable encryption method and decrypt the key.

This lets Hexnode store the updated recovery key for future recovery scenarios.

Regards,
Mary Romero

Save