macOS devices show not encrypted when FileVault policy is enabledSolved

Participant
Discussion
20 hours ago Aug 13, 2026

I have a couple of Macs showing as not encrypted in Hexnode even though our macOS policy has FileVault enabled and users are not allowed to disable it. Is there another setting I should adjust to make sure FileVault is always enforced on these devices?

Replies (3)

Marked SolutionPending Review
Hexnode Expert
16 hours ago Aug 13, 2026
Marked SolutionPending Review

If FileVault is enabled in the macOS policy but the device still appears as not encrypted, first confirm whether the FileVault policy was actually applied to those Macs. Recommended checks:

  1. Open the device in Hexnode and review the device action history.
  2. Confirm that the macOS policy containing the FileVault configuration is listed as applied successfully.
  3. Check whether the devices are included in the correct policy target, such as the right device group, user group, or dynamic group.
  4. If the policy was recently assigned, allow some time for the device to sync with Hexnode.
  5.  Restart the Mac and then check the encryption status again.

If only a default compliance policy is active on the device, FileVault enforcement from the intended macOS policy will not take effect until that policy is correctly scoped and applied.

Marked SolutionPending Review
Participant
7 hours ago Aug 13, 2026
Marked SolutionPending Review

Found the issue. The actual Mac device policy was not applied to those two devices. They only had the default compliance policy active. Looks like the policy conditions had not caught up for them yet.

Marked SolutionPending Review
Hexnode Expert
48 minutes ago Aug 14, 2026
Marked SolutionPending Review

That would explain the behavior. Once the correct macOS policy is applied, Hexnode can enforce the FileVault configuration on the device. After applying the policy, wait for the device to sync and then verify the action history again. If the FileVault policy shows as applied, restart the Mac if the encryption status does not update immediately. The device should report as encrypted once FileVault is enabled and the updated status is synced back to Hexnode. To prevent this from happening again, it is a good idea to verify the policy targets or dynamic group conditions used for FileVault enforcement, especially for newly enrolled or recently reassigned Macs.

Save