Is IRK deprecating?

carin@
expand collapsive

Hi folks,
Can someone provide some insight on whether we can decrypt mac using IRK on m1 chip devices. Happened to see that using IRK to unlock macs is turning obsolete.

Tags:

All Replies

  • 96anneette

    96anneette

    Participant

    96anneette

    Participant

    I’m also trying to access an encrypted drive with only IRK. Does that work any more with catalina? checked it with a t2 equipped macbook pro nd with catalina VM. In the recovery mode the screen shows the list of users and ask to enter one of their passwords. Another way I can tap forgot passwords but then it asks me to provide a PRK or icloud account.

    Is it that I’m doing anything wrong or are these keys not supported any more? Hope someone can shed some light on this matter.

  • ida-sol

    ida-sol

    Participant

    ida-sol

    Participant

    Creating an IRK for mac is a thing of the past now. Over these years, the PRK gained both popularity and functionality while the IRK did not. The chief advantage of IRK to be used as the recovery key for mass deployments is now considered as a pitfall owing to the introduction of PRK escrow systems (common in modern MDM solutions). Another limitation is the danger of a compromised recovery key that will be able to unlock and access all the devices in your institution. Hence it’s always better to have a single unique key for each machine. Apple itself does not recommend the use of IRKs for institutional deployments anymore.

  • Jeff Morrison

    Jeff Morrison

    Hexnode

    Jeff Morrison

    Moderator

    Hey @Carin and @96anneette, thanks for reaching out to us!

    Starting from macOS Big Sur and for Mac with M1 chip, you cannot use the Institutional Recovery Key (IRK) for decryption. You can access Utilities in the Recovery Mode only by authenticating with the admin credentials or the Personal Recovery Key (PRK). As mentioned by @ida-sol, Apple no longer recommends using an IRK for institutional management of FileVault on Macs.

    You may also have a look at the Manage FileVault documentation for further clarity.

    Hope this answers your query.

    Thanks!
    Jeff Morrison
    Hexnode UEM

  • Jeff Morrison

    Jeff Morrison

    Hexnode

    Jeff Morrison

    Moderator

    @ida-sol That’s very well said! For Macs with Apple Silicon or Intel-based devices, it’s ideal to escrow the PRK into the Hexnode server instead of using an IRK.

    Looking forward to hearing more from you.

    Cheers!
    Jeff Morrison
    Hexnode UEM