MacOS – Disable a user’s ability to unlock a FileVault 2 volume at startup/login time

filevaultmacos

I recently performed a clean install of Lion on one of my Macs. The installation process created one administrative user account. After installation, I enabled FileVault for the entire disk. Then, I created an additional administrative user. Both users are able to decrypt the drive during login.

How would I revoke decryption rights to one of the users without deleting the user or temporarily disabling FileVault? I have tried revoking one user's administrative privilege, making them a regular user, but they are still able to decrypt the drive during boot.

Best Answer