Forgotten passwords or unavailable users don’t have to turn into roadblocks anymore. With FileVault key rotation, you can now reset user passwords securely while ensuring recovery keys stay valid and protected. 

This aligns with Apple’s recommendations to keep FileVault keys fresh and uncompromised.

What you can do:

  • Configure automatic rotation frequency (1–360 days).

  • Prompt users if silent rotation fails, with a custom message and timeout.

  • Set periodic validity checks and auto-rotate invalid keys.

  • Rotate keys on demand from the Device Details section of the dashboard.

  • View historical key changes and the last validation time.

You can also leverage the following reports to stay audit-ready:

  • FileVault Status Report: See FileVault details across all devices at a glance.

  • Rotation History Report: Track all rotation events and statuses.