MacOS – FileVault: How come a new user can log in without disk password

encryptionfilevaultmacos

I thought I had enabled full volume encryption on my OS X 10.9.5 MBP. Then I created a new user and when rebooting, this new user is able to log in without knowing the password for the disk.

The start up screen is presented with the new user to the left and the normal "Unlock disk" (or something like that) icon to the right – if I want to log in with my normal admin account, I first have to unlock the disk and then my user becomes visible.

What gives?

Best Answer

From Apple KB - Use FileVault to encrypt the startup disk on your Mac
Emphasis mine...

Enable users

If you enable FileVault on a Mac with more than one user account, you're asked to identify which users can unlock your startup disk as part of setup. Click Enable next to a user name to let that user log in to your Mac at startup. Then, enter the password for that account.

Users that you don't enable can't unlock the startup disk. These users aren't able to use your Mac until after an enabled user logs in.

Any new user accounts you create after you turn on FileVault are automatically enabled.