Apple Revises macOS 28 Migration Guidance for Encrypted HFS+ Drives

The transition of the Apple ecosystem toward its modern file system architecture has reached a significant milestone with the recent update to technical documentation regarding macOS 28. Apple has officially revised its migration guidance for users maintaining legacy encrypted volumes, introducing a streamlined pathway for converting Mac OS Extended (HFS+) drives to the Apple File System (APFS). This policy shift addresses a critical friction point for long-time Mac users who possess high-capacity external storage arrays or archival drives protected by legacy encryption methods. Previously, the move to macOS 28 appeared to necessitate a multi-step decryption process or a complete drive reformat, but the new "direct conversion" option aims to preserve data integrity while modernizing security protocols.
The Evolution of Apple File Systems: From HFS+ to APFS
To understand the significance of this update, one must look at the historical trajectory of Apple’s storage technology. For nearly two decades, the Hierarchical File System Plus (HFS+), also known as Mac OS Extended, served as the primary file system for the Macintosh. Introduced in 1998 with Mac OS 8.1, HFS+ was designed for an era of spinning hard disk drives (HDDs) and limited file sizes. While it was robust for its time, the advent of solid-state drive (SSD) technology and massive data throughput requirements exposed its architectural limitations, such as its 32-bit timestamps and lack of native snapshot capabilities.
In 2017, with the release of macOS High Sierra, Apple introduced APFS. This new system was built from the ground up for flash and SSD storage, featuring 64-bit inodes, space sharing, clones for files and directories, and native encryption. Since its debut, Apple has been systematically phasing out HFS+ support for internal boot drives, though the legacy system remained functional and supported for external storage and mechanical drives. However, as macOS continues to evolve toward a more secure, snapshot-based architecture, the compatibility layer for legacy encrypted HFS+ volumes has become a technical debt that the company is now moving to resolve with the upcoming release of macOS 28.
The macOS 28 Mandate: Sunsetting Encrypted Legacy Volumes
The initial announcement regarding macOS 28 and HFS+ sent ripples through the professional creative and IT sectors. In early July 2026, Apple published a support document clarifying that macOS 28 would strictly limit support for the Mac OS Extended format. Specifically, the operating system would no longer support volumes that utilize HFS+ in conjunction with legacy encryption. While unencrypted HFS+ drives will remain mountable for read/write access, any drive utilizing the older Core Storage encryption method (often used by FileVault 2 on HFS+) would become inaccessible unless migrated.

The original guidance provided by Apple was relatively rigid. Users were instructed to either decrypt the entire volume—a process that could take several days for multi-terabyte drives—or to back up the data elsewhere, erase the drive using APFS, and then move the data back. This presented a significant logistical challenge for users with massive data archives or those working in secure environments where unencrypted data, even temporarily, is a violation of protocol.
A Shift in Guidance: The Direct Conversion Pathway
Recognizing the potential for data loss and user frustration, Apple has updated its support documentation to include a third, more efficient option: direct in-place conversion from encrypted HFS+ to encrypted APFS. This new method allows the operating system to rewrite the file system metadata without requiring the user to first remove the encryption layer.
The updated process is integrated into the Disk Utility application and the command-line interface, allowing for a seamless transition. According to the revised documentation, users can now right-click an encrypted HFS+ volume in the Finder or use Disk Utility to trigger a conversion that maintains the encrypted state throughout the process. This "in-place" migration is designed to be significantly faster than a full decryption-re-encryption cycle because it modifies the file system structure while leveraging the existing cryptographic headers where possible, or translating them directly into APFS-native encryption.
Technical Mechanics and Safety Protocols
The conversion process involves a complex remapping of the drive’s B-tree structures (used by HFS+) into the space-efficient extent-based metadata used by APFS. When converting an encrypted volume, macOS must also transition the volume from the Core Storage wrapper—a logical volume manager used by legacy macOS—into a native APFS Container.
Technical analysts note that this direct conversion is a high-stakes operation. Because the file system is being rewritten at a fundamental level, any interruption in power or hardware failure during the process could lead to catastrophic data loss. Apple’s revised guidance emphasizes that while the direct conversion is now an official feature, it remains a best practice to have a secondary, verified backup before initiating the transition. The "in-place" nature of the tool means that the metadata is being moved and transformed on the same physical sectors, leaving little room for error if the process is compromised.

Chronology of the Transition
The timeline of this policy change reflects Apple’s iterative approach to macOS 28 compatibility:
- July 8, 2026: Apple releases the first public warning that macOS 28 will drop support for encrypted Mac OS Extended volumes. The documentation suggests only decryption or reformatting as solutions.
- Mid-July 2026: Feedback from enterprise users and the Mac admin community highlights the impracticality of decrypting petabytes of archival data across global organizations.
- Late July 2026: Apple updates support document ID 125615, introducing the "Convert to APFS" option for encrypted volumes and removing the previous cumbersome instructions that required manual decryption.
- Current Status: The revised guidance is now the official standard for developers and beta testers preparing hardware for the macOS 28 launch.
Exceptions to the Rule: The Case of Time Machine Backups
A critical caveat in Apple’s revised guidance is the exclusion of Time Machine backup disks. Apple explicitly states that the direct conversion solution does not apply to encrypted Time Machine volumes formatted in HFS+.
The reason for this exception lies in the fundamental difference between how HFS+ and APFS handle Time Machine. Legacy Time Machine (HFS+) relies heavily on "hard links" for both files and directories to create the illusion of full backups while saving space. APFS Time Machine, introduced in macOS Big Sur, uses a completely different mechanism based on "APFS Snapshots." Because these two architectures are fundamentally incompatible, an in-place conversion of a Time Machine database is technically unfeasible without risking the integrity of the backup history. Users with encrypted HFS+ Time Machine drives will still need to start fresh backups on APFS-formatted drives when moving to macOS 28, a move Apple has encouraged since 2020.
Industry Impact and User Preparation
The shift in guidance has been met with cautious optimism by IT professionals. "The ability to convert in-place saves hundreds of man-hours for departments managing legacy external drive pools," says Marcus Thorne, a senior systems architect specializing in macOS deployments. "However, the exclusion of Time Machine means that the ‘clean slate’ approach for backups is still a requirement, which is often where the most significant data volume resides."
For the average user, the implications are clear: macOS 28 is the final signal that the HFS+ era is ending for anything beyond simple, unencrypted file transfers. To prepare, users should:

- Identify all external drives using the "Get Info" command in Finder to check the format.
- Ensure any drive labeled "Mac OS Extended (Journaled, Encrypted)" is prioritized for conversion.
- Verify that they have a secondary backup of the data on these drives.
- Utilize the new Disk Utility conversion tool to modernize the drive format before the official upgrade to macOS 28.
Hardware Performance Considerations
While APFS is optimized for SSDs, many legacy encrypted HFS+ drives are traditional mechanical HDDs. There has been ongoing debate regarding APFS performance on spinning disks, as the file system’s metadata-heavy operations can lead to "disk thrashing" on slower hardware. However, Apple’s move to mandate APFS for encrypted volumes suggests that the security benefits and architectural consistency of APFS now outweigh the potential performance overhead on legacy mechanical hardware.
As macOS 28 approaches, this revision in guidance demonstrates Apple’s recognition of its long-term user base. By providing a direct conversion path, the company is attempting to balance the aggressive modernization of the Mac platform with the practical realities of data management for users who have decades of information stored on Apple-formatted hardware. The move effectively removes one of the last major hurdles for the total adoption of APFS across the Mac ecosystem.




