macOS can be configured to destroy its retained FileVault key when the Mac enters standby. The next wake from standby then requires an authorized FileVault user to enter their password again.
This is an advanced hardening option, not a replacement for turning on FileVault. It is mainly relevant when your threat model includes physical access to a sleeping Mac.
The earlier description of the key being stored in an “EFI BIOS” was not accurate. On Macs with Apple silicon or the Apple T2 Security Chip, Apple says FileVault key handling for the internal storage takes place in the Secure Enclave and the keys are not directly exposed to the CPU.
Before you change the setting
- Confirm that FileVault is on and that you have a working recovery method.
- Save your work and keep a current backup.
- Expect a slower wake and another password prompt after the Mac has actually entered standby.
- On a managed Mac, ask your administrator. Apple provides the same setting through a FileVault device-management payload.
Ordinary sleep and standby are not identical. macOS may enter standby only after it has been asleep for some time, and behavior depends on the Mac and its power settings. Do not change hibernatemode only to make this check pass.
How to fix it
macOS 10.11 and later
-
Open Terminal.
-
Enter the following command and press Return:
sudo pmset -a destroyfvkeyonstandby 1 -
Enter your administrator password when prompted. Terminal does not show characters while you type the password.
-
Verify the stored value with:
pmset -g customLook for
destroyfvkeyonstandby 1in the relevant power profile. If the setting is not shown or the Mac does not behave as expected, do not assume that this hardening is active. -
Test sleep and standby before relying on the setting.
The -a option applies the value to battery, charger, and UPS power profiles supported by the Mac.
How to undo it
To retain the FileVault key across standby again, run:
sudo pmset -a destroyfvkeyonstandby 0Then confirm the value with pmset -g custom.
Security boundary
This setting reduces how long a retained FileVault key remains available while the Mac is in standby. It does not protect an already unlocked session from malware, remote access, or someone using the Mac before it reaches standby. Lock the screen whenever you leave the Mac and keep macOS up to date.
Sources
- Apple Platform Deployment: Intro to FileVault
- Apple Platform Deployment: FileVault device management payload settings
- The built-in macOS
pmset(1)manual (man pmset), which documentsdestroyfvkeyonstandbyand standby behavior.

