Remote wipe on Macs: what it achieves, by hardware
Cryptographic wipe on encrypted Macs; what changes when FileVault is off; why Find My matters.
- 1FileVault ON (any Mac): disabling FileVault discards the volume key, so every byte becomes cryptographically unrecoverable within seconds — equivalent to an erase for data-protection purposes. Then user data is destroyed, every local account is deleted, and the Mac reboots unusable.
- 2FileVault OFF on an Apple silicon or T2 Mac (2018 onward): the internal SSD is always hardware-encrypted by the Secure Enclave, so a removed drive yields nothing. After the wipe deletes the data, the SSD discards freed blocks (TRIM); recovery would require forensic tooling and luck. Strong — but not the instant certainty FileVault gives.
- 3FileVault OFF on an older Intel Mac without T2: the disk is genuinely unencrypted and deleted files can be partially recovered by anyone who removes the drive. The agent additionally overwrites all free space with random data — effective against ordinary recovery, not a guarantee against a forensic lab.
- 4Advance hygiene (one click per Mac, by the user): turn on FileVault (System Settings → Privacy & Security → FileVault) and Find My (System Settings → Apple ID → iCloud → Find My Mac). Cybermatic raises a high-severity finding for any Mac without FileVault so you see it on an ordinary day, not during a theft.
- 5Full factory erase (Erase All Content and Settings) can only be issued by an MDM the Mac is enrolled in — Apple permits no other path. If you already run Microsoft Intune, connect it (Settings → Microsoft Intune) and remote wipe also issues Intune's erase automatically.
Tip: The wipe result on the Response page records the device's FileVault, Secure Enclave, and Find My state at the moment it acted — keep it for your incident record.