During a visit to a mental asylum, a visitor asked the Director what are the criteria that define whether a patient should be institutionalized. "Well," said the Director, "we filled a bathtub, then we offered a teaspoon, a cup of tea and a bucket to the patient and asked the patient to empty the tub." Well, here is your test: 1. Would you use the spoon? 2. Would you use the cup of tea? 3. Would you use the cube? "Oh, I understand," said the visitor. "A normal person would choose the cube, since it is bigger than the spoon". What was the director's response?

"No," the director replied. "A normal person would pull the plug".

Mobile device management: An error message appears when you unlock a FileVault APFS volume with an institutional recovery key

I am testing an MDM solution (with an internal MDM instance), which applies FileVault. It is configured with an institutional recovery key (IRK) and a personal recovery key (PRK). The latter is also saved in MDM.

Basically, we generate a keychain like this, export the keychain certificate and add it to an MDM profile (we are using the MDM of

It is working very well. When I do a diskutil apfs listCryptoUsers diskNxM, I get all the users I expect, including a user of type Institutional Recovery User and one with type Institutional External Key Recovery. Resetting the password through Open Directory works fine. Unlocking the unit with the PRK works well.

And now I'm trying to unlock the volume with said IRK.
I started via recovery (cmd + R), and when I execute diskutil apfs unlockVolume / dev / diskNsM -recoveryKeyChain /Volumes/RecoveryDrive/FileVaultMaster.keychain (the keychain is unlocked and the unit is correct), this error appears:

Error unlocking APFS volume: unpacking credentials from external security system to APFS
failed operation (-69534)

I verified the unlocking of the keychain with a different password, and that failed directly. Someone here suggested removing the keychain certificate. This did not work either.

Any ideas (besides creating a new FileVault Master keychain and doing the whole process one more time)?

