|Managing Mac endpoints / About SafeGuard Native Device Encryption for Mac|
Usually it is not necessary to decrypt. If you set a policy that specifies No encryption for Mac clients that are already encrypted, they will remain encrypted. However, in this case, users have the choice to decrypt. They will find the corresponding button in the Disk Encryption tab of the preference pane.
Users with local administrator rights cannot be prevented from attempting to manually decrypt their hard disk using built-in FileVault 2 functionality. However, they will be prompted for a restart to complete the decryption. As soon as the Mac has completed the restart, SafeGuard Native Device Encryption for Mac will enforce encryption if a corresponding policy has been set.