macOS does not add a password directly to an ordinary Finder folder. For selected files, create an encrypted, password-protected disk image in Disk Utility; for the whole Mac, turn on FileVault. Use an encryption-capable archive when sending a fixed bundle, and consider Cryptomator or VeraCrypt for cloud or cross-platform workflows.
Choose the protection that matches your goal
| Need | Best method | Main drawback |
|---|---|---|
| Protect selected files or one folder on a Mac | Encrypted Disk Utility image | You must mount and eject the image |
| Protect the entire Mac if it is lost or stolen | FileVault | It protects the startup volume, not one folder |
| Protect a USB drive or external disk | Encrypted APFS volume | The erase workflow can destroy existing data and compatibility is limited |
| Send a fixed file bundle | Encryption-capable archive | Less convenient for editing and dependent on compatible software |
| Store encrypted files in cloud storage | Cryptomator-style vault | Requires third-party software and careful synchronization |
| Work across macOS, Windows and Linux | VeraCrypt or a modern encrypted archive tool | More setup than Apple’s native workflow |
Encryption makes data unreadable without a key or password. A Mac login password, Unix file permissions and FileVault address different threats. FileVault protects data at rest on the startup disk; it does not create a second password prompt for a normal Finder folder.
Create an encrypted disk image for files or a folder
An encrypted disk image is a password-protected container that mounts as a virtual drive. Apple recommends this approach for confidential documents. See Apple’s Disk Utility guide.
Make a blank read/write image (best for an active vault)
- Open Disk Utility from Applications > Utilities.
- Choose File > New Image > Blank Image.
- Enter a filename and choose where to save the
.dmgfile. - Give the mounted volume a name.
- Set a size large enough for the files. A fixed-size image cannot accept data after it is full; a sparse or sparse-bundle image can grow as files are added, but the backing storage still needs enough free space.
- For a modern Mac, choose APFS or APFS (Case-sensitive) when you specifically need case-sensitive behavior. Case-sensitive storage can confuse applications that expect case-insensitive filenames.
- Choose an option from Encryption, then create and confirm a long, unique password.
- Leave Single partition – GUID Partition Map and the read/write image format selected unless you have a specific reason to change them.
- Click Save, then Done.
- Copy the files or folders into the newly mounted volume in Finder.
The result is an encrypted .dmg file and, immediately after creation, a mounted volume. The copy inside that volume is protected when the image is closed; an unencrypted copy elsewhere is not.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Hardware encrypted drive
- Simple to use pin access. RPM-5400
- Administrator password feature
- Bus powered
- Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm
Create an image from an existing folder
Some macOS versions offer File > New Image > Image from Folder. Select the folder, choose encryption and set a password. Check the resulting image’s format: a read-only image is suitable for a protected snapshot, but not for a folder you will keep editing. A blank read/write image is generally the more flexible working vault.
Open, use and eject the encrypted image
- Double-click the
.dmgfile. - Enter its password. The encrypted volume appears in Finder like a drive.
- Open and edit files inside that mounted volume normally.
- When finished, click the volume’s eject button in Finder or drag it to the Trash/Eject icon.
While mounted, the files are available to the logged-in session and to applications permitted to access them. Do not leave a sensitive image mounted on a shared or unattended Mac. The .dmg remains encrypted after it is ejected.
Apple warns that a forgotten disk-image password prevents the image from being opened; there is no normal Apple reset or backdoor. Keep the password in a reputable password manager or another secure location separate from the image.
Secure the originals and other copies
Creating an encrypted image protects only the copy placed inside it. Before deleting anything, unlock the image and open representative files, verify that a backup of the encrypted container exists, and confirm that you know the password. Only then decide whether to remove and empty the original unencrypted files; that action is irreversible.
Recommended Free Tools
- Check Downloads, Desktop, Documents, iCloud Drive and other synchronized folders.
- Look for exported PDFs, duplicate attachments and files copied out for editing or sharing.
- Remember that application temporary files, previews, backups and cloud-provider retention copies may remain separate from the image.
- Keep a backup of the encrypted container itself, and test restoring it.
Protect the entire Mac with FileVault
Use FileVault when your concern is a lost or stolen Mac or unauthorized access to its internal storage while it is powered off or locked. FileVault encrypts the startup volume; it does not add folder-level passwords after you have logged in.
- Open the Apple menu and choose System Settings > Privacy & Security > FileVault.
- Click to turn on FileVault. Administrator access is required.
- Choose whether recovery uses your iCloud account or a generated recovery key.
- If you receive a recovery key, store it somewhere safe and separate from the Mac.
- Enable any additional user accounts that should be allowed to unlock the encrypted startup disk.
Apple states that losing both the account credentials and the recovery key can permanently prevent access to the files. See Apple’s FileVault instructions.
Rank #2
- Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm
- Super fast USB 3.0 Connection - Data transfer speeds up to 10X faster than USB 2.0
- Software Free Design - With no admin rights needed
- Sealed from Physical Attacks by Tough Epoxy Coating
- Brute Force Self Destruct Feature
Apple-silicon and T2 Macs encrypt internal storage automatically using hardware security features; enabling FileVault connects access to user credentials and provides the recovery workflow. Older Intel Macs generally require FileVault to be enabled for startup-disk encryption. FileVault does not protect unencrypted copies on other drives, cloud services or removable media, and after login applications can access files according to permissions.
Encrypt a USB drive or external disk
Encrypting an entire external device is useful for a dedicated confidential drive or backup disk, but Apple’s Disk Utility workflow erases the selected device. Back up everything first.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →- Open Disk Utility and choose View > Show All Devices.
- Select the storage device or volume.
- Click Erase and enter a name.
- Choose GUID Partition Map as the scheme.
- Choose an encrypted file-system format, set and confirm its password, then click Erase and Done.
Encrypted removable media may be converted to APFS and may not open on older macOS versions that do not support APFS. Check compatibility before relying on the drive with another Mac or device; Apple’s guidance is at this Disk Utility page.
If you cannot erase the drive, keep its existing format and place an encrypted disk image on it instead. That protects selected data without reformatting the whole device.
Use an encrypted archive when sending files
An archive is a good one-time package or fixed snapshot, but it is less convenient than a mounted vault for ongoing edits. Finder’s ordinary Compress command is not a universal encrypted-folder solution, and a password prompt does not identify the encryption standard.
For a compatibility-oriented Terminal option, macOS includes:
Rank #3
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
zip -er protected.zip "Folder to Protect"
-e prompts for a password and -r recursively includes the folder. The built-in workflow is not automatically equivalent to a modern AES-encrypted archive. For higher assurance, use a maintained archive tool that explicitly supports AES encryption, test extraction on the exact macOS release and recipient system, and send the password through a different channel. Extracting an archive can create unencrypted copies, and archive filenames or other metadata may remain visible depending on the format.
Cloud and cross-platform alternatives
Cryptomator for cloud-backed vaults
Cryptomator is designed for encrypted vaults stored in cloud-synchronized locations. Its published materials describe encryption of file contents and filenames. It can be a better fit than repeatedly syncing one mounted DMG, but it is third-party software: understand how its vault files synchronize, avoid simultaneous edits from multiple Macs, and plan for password loss. See the Cryptomator site and its Mac product listing.
VeraCrypt for broader interoperability
VeraCrypt provides free, open-source encrypted containers with macOS support. Its current download documentation discusses macOS Monterey 12 and later and recommends a FUSE-T-based version for Apple-silicon Macs. It can suit Windows/Linux interoperability, but installation, filesystem support and mounting are more complex than Disk Utility. Consult the official downloads page and test the complete workflow before moving valuable files.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshoot common problems
“The original folder is still visible.”
You encrypted a copy, not the original. Check local folders, synchronized locations, backups and exported files before deciding whether to delete the originals.
Free tools Windows power users keep installed
One-click scans. No signup required.
“I forgot the password.”
An encrypted disk image normally cannot be opened without its password. FileVault may offer the configured account recovery route or recovery key; losing both can mean permanent data loss.
“The image is full.”
A fixed-size read/write image has reached its limit. Restore from a verified backup and create a larger image or choose an appropriate sparse format rather than casually resizing a live container.
Rank #4
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
“It will not open on Windows.”
Encrypted Apple disk images are primarily Mac-native. Use a tested cross-platform archive, VeraCrypt or Cryptomator when the recipient uses Windows or Linux.
“No password prompt appears.”
The image may already be mounted, Finder may have retained credentials in the keychain, or the file may not actually be encrypted. Eject the mounted volume and reopen the container to test it. For archives, verify that the utility and format support encryption.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minute“FileVault is on, but another user can read my files.”
FileVault protects data at rest and the startup volume. Once the Mac is unlocked, separate user accounts, file permissions, application controls or an encrypted per-folder vault are still needed.
“My cloud-synced DMG has conflicts.”
Do not mount and edit the same image simultaneously from multiple Macs. Synchronization during writes can produce conflicts or incomplete containers; use a purpose-built vault for that workflow.
Practical security checklist
- Use a long, unique passphrase and keep it outside the protected container.
- Test unlocking and opening files before deleting originals.
- Eject disk images when you finish or leave the Mac.
- Back up the encrypted image or drive and test restoring it.
- Share archive passwords separately from the archive itself.
- Test compatibility with the recipient’s actual operating system.
- Remember that files copied outside a mounted vault are no longer protected by that vault.
The Bottom Line
For most Mac-only users protecting a small set of files, an encrypted read/write Disk Utility image is the simplest built-in answer. Turn on FileVault for whole-Mac protection, use an encrypted archive for one-time delivery, and choose Cryptomator or VeraCrypt when cloud synchronization or non-Mac compatibility is central.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




