Hard Drive Encryption
Here are step-by-step instructions for setting up hard drive encryption on a device.
Windows:
To enable device encryption, please complete the following instructions from Microsoft:
Select Start > Settings > Privacy & security > Device encryption.
If Device encryption is turned off, turn it On.
If Device encryption doesn't appear, it isn't available for your device.
Mac:
To pass this check, FileVault must be enabled.
To enable Filevault (instructions from here):
On your Mac, choose Apple menu > System Settings, click Privacy & Security in the sidebar, then click FileVault on the right. (You may need to scroll down the right-side list.)
Click Turn On. You might be asked to enter your password.
Choose how to unlock your disk and reset your login password if you forget it:
iCloud account: Click “Allow my iCloud account to unlock my disk” if you already use iCloud. Click “Set up my iCloud account to reset my password” if you don’t already use iCloud.
Recovery key: Click “Create a recovery key and do not use my iCloud account.” Write down the recovery key and keep it in a safe place.
Click Continue.
Linux:
This checks for the following configurations for the hard drive:
The drive mounted as
rootneeds to be encrypted. The encryption process will vary based on the flavor of Linux being used.ZFS encryption is not currently supported because of a limitation in osquery.
*If your Linux device is not 'checking in' after restarting, please refer to this article.
Frequently Asked Questions (FAQ)
I can’t pass Hard drive encryption for user endpoints (Secureframe Agent) because BitLocker needs Windows Pro or higher. What should I do?
You have 2 options to resolve a situation like this.
Option 1. Upgrade affected devices to Windows Pro/Enterprise and enable BitLocker. Once complete, re-run the test after encryption is enabled.
Option 2. Upload additional evidence + ignore agent evidence for the specific user.
Open the test, click the Evidence tab, scroll down to Additional Evidence.
Click Add evidence and upload evidence demonstrating encryption on the system if applicable
In the Evidence list, open the 3 dot menu next to the affected user → Ignore evidence for this test (since you provided manual evidence).
Add a justification comment (sample below) and save.
Re-run the test to update evidence with the failing result ignored for that user.
Acceptable evidence to upload:
Screenshot showing OS edition (Windows Home/Pro) and encryption status
Settings → Privacy & Security → Device encryption (or BitLocker control panel) showing On/Off
List of affected endpoints (hostname, user, OS edition)
Your policy requiring full-disk encryption
Risk acceptance/exception record with a remediation plan & target date
Note: Sample justification text for ignoring evidence: “Endpoint is on Windows Home; BitLocker requires Pro/Enterprise (Microsoft licensing limitation). We are tracking an exception and will upgrade to Windows Pro and enable BitLocker by [date]. In the interim, the device is covered by [compensating control, if any]. Evidence attached.”
FileVault is on, but Hard Drive Encryption still fails. What should I check?
Confirm the Secureframe Agent is installed on that Mac, checking in, and reporting encryption status on the device record.
Confirm FileVault is fully on (not still encrypting), then wait for the next Agent sync and re-check the test.
If the employee has more than one device, open the failing evidence row and confirm which hostname is failing. It may not be the Mac with FileVault on.
If the Agent still cannot report encryption, upload a FileVault status screenshot as additional evidence, ignore the Agent fail for that user with a short justification, and re-run the test.
Can one employee with two devices cause Hard Drive Encryption to fail? Which device is evaluated?
Yes. The test evaluates devices linked to the employee. One unencrypted or stale/no-Agent device can fail the user even if another device is encrypted.
Open the test evidence for that user and check hostname, OS, and Agent status per device. Encrypt or fix the failing device, archive/remove devices no longer in use, or upload manual evidence and ignore the Agent result when appropriate.
Re-run the test or wait for the next Agent sync.
Can third-party full disk encryption meet the requirement when BitLocker is unavailable (for example Windows 10 Home)?
Yes, for many SOC 2 setups, third-party full disk encryption can satisfy the control when BitLocker is unavailable, if you can prove it is active and your policy allows it. Confirm with your auditor.
The Secureframe Agent expects BitLocker / Device encryption on Windows and FileVault on Mac, so third-party tools usually will not auto-pass.
Upload proof on the test (encryption tool showing On/encrypted, plus policy or exception notes if needed), ignore the Agent fail for that user with a justification, and re-run the test. Use the same upload + ignore steps as the Windows Home BitLocker FAQ in this article.
