Apple has formally deprecated encrypted HFS+ drives in macOS 27, and the clock is now running for anyone still backing up to old encrypted external disks. The macOS 27 release notes list Encrypted HFS+ (CoreStorage) as deprecated, and a separate support document confirms macOS 28, due in 2027, will support the Mac OS Extended format only for volumes that are not encrypted.
In practice that means any encrypted external hard drive formatted in the old Mac OS Extended style will stop working on a Mac running macOS 28 unless the user decrypts it or reformats it first. Apple has not explained the decision, but the direction has been clear since APFS became the default file system on the Mac with macOS High Sierra in 2017. APFS handles encryption natively, and encrypted HFS+ depends on the much older CoreStorage layer that Apple has been quietly winding down for years.
Who is affected
The change hits a specific and shrinking group: users with older encrypted external drives, including many Time Machine backup disks formatted before APFS became standard. Unencrypted Mac OS Extended volumes are not affected. Apple says macOS 28 and later will continue to support plain HFS+ volumes, so this is a deprecation of the encrypted variant, not the format as a whole.
Warning signs start before the cutoff. Beginning with macOS 26, a Mac may notify users when it detects an encrypted Mac OS Extended disk that will not carry over to macOS 28, identifying the affected volume by name. Users can also check manually in Disk Utility by selecting a volume and reading the format details under its name. A volume showing both Mac OS Extended and Encrypted, such as a CoreStorage logical volume listed as case-sensitive, journaled and encrypted, is incompatible with the next major release.
The affected population is larger than it might seem. External hard drives sold through the mid-2010s were commonly shipped formatted as encrypted HFS+ out of the box, and plenty of them are still in desk drawers running nightly backups. Time Machine itself defaulted to HFS+ on network-adjacent disks for years. Anyone who bought a backup drive before roughly 2017 and ticked the encryption box in Disk Utility has exactly the volume type Apple is retiring.
The two ways out
Apple offers two paths, and the right one depends on what the drive holds. The first is decryption: connect the drive, unlock it with its password, then Control-click the volume in the Finder and choose Decrypt. The data stays in place, though the process takes time on large volumes and progress can be checked in Terminal. After decryption, the volume can be converted to APFS in place via Disk Utility without erasing it, then re-encrypted if wanted.
The second path is reformatting, which means erasing the drive entirely and setting it up as APFS or APFS Encrypted. That permanently deletes the data, so a backup comes first. For most users with a drive full of old archives, decrypt-then-convert is the safer route because nothing is destroyed along the way.
There is one important exception. The decryption path does not apply to encrypted Time Machine backup disks. Time Machine interacts with HFS+ in ways that make in-place conversion unreliable, so an encrypted HFS+ Time Machine drive needs its encryption removed or the backups migrated to a new APFS-formatted disk before upgrading to macOS 28.
| Option | Keeps data | Best for |
|---|---|---|
| Decrypt in place | Yes | Archive drives with data worth keeping |
| Decrypt, then convert to APFS | Yes | Drives that should stay encrypted long term |
| Reformat to APFS | No | Drives due for a clean start anyway |
Why Apple is doing this
CoreStorage, the logical volume manager behind encrypted HFS+, dates back to OS X Lion in 2011 and was Apple’s first consumer encryption stack. APFS replaced it with a design built for SSDs and native encryption from the ground up. Maintaining two encryption paths for a decade is expensive, and the deprecation notice in the macOS 27 release notes tells developers and users the same thing in the same breath: begin backing up to encrypted APFS-formatted external drives instead.
The wider context is a broader pruning of legacy Mac technology. The macOS 27 cycle has also deprecated Time Capsule support, the DVD Player framework, and groundwork for eventual Rosetta removal, with Intel applications that will not run in macOS 28 now flagged in Get Info. Encrypted HFS+ joins a list of technologies Apple is retiring on a published schedule rather than silently, which at least gives users a year to act.
One practical wrinkle for the community that maintains old machines: Linux distributions such as Debian and Ubuntu have long restricted mounting of HFS+ partitions above 2 TB, so cross-platform users juggling old Mac drives already deal with format friction. Removing encrypted HFS+ from macOS reduces one compatibility surface but adds another migration task.
The deadline
The cutoff is concrete. macOS 28 arrives in 2027, and any encrypted HFS+ volume connected to a Mac running it will be unreadable until decrypted or moved. The warning system Apple built into macOS 26 and 27 does most of the work for attentive users, flagging the exact volume by name. For everyone else, checking Disk Utility today takes two minutes. Discovering the problem after an upgrade takes considerably longer, especially when the volume in question is the only copy of a decade of backups.
