Call us — 0141 404 0294
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · NAS & Network Storage · No Other Action Taken

A Mac Array That Met a Windows Machine

His enquiry was four lines and one of them is the most valuable thing in it. A Mac external RAID enclosure"accidentally plugged into a PC. macOS not seeing the drive any more. No other action taken. Can you help? I'd like to retrieve all data." That last phrase, no other action taken, is the difference between a straightforward job and a difficult one, and he was right to say it. But the case is worth writing down for a reason that surprises people: a Windows machine can alter a disk without being asked to, and declining the obvious prompt is not always the end of what it does.

MediaMac-formatted external RAID enclosure — connected in error to a Windows machine; subsequently not recognised by macOS; no further action taken by the owner
Reported situationArray connected accidentally to a Windows PC · no longer visible to the Mac afterwards · no formatting, initialising or repair performed by the owner · complete recovery required
Fault classArray or partition structures altered by an unfamiliar host — member data intact; recognition lost at the structural layer
Equipment usedEnclosure powered down · members removed, labelled and imaged write-blocked (Atola TaskForce 2) · array geometry derived from the images · volume reassembled offline; contents verified by opening

The decode: what Windows does uninvited, and why his line matters

What happens when Windows meets an unfamiliar disk: it cannot read Mac filesystems, so it concludes the disk is uninitialised and offers to initialise it. Everybody knows to decline that. What fewer people know is that Windows may also, as part of ordinary disk enumeration, write a disk signature to the start of a disk it does not recognise — a small identifier used to track the device, written without a prompt and without any sense of having done something. On a plain disk that is usually harmless. On an array member, where the very start of the disk carries the structures identifying it as part of a set, it can be enough to break recognition.

Why his Mac then stopped seeing it: that is consistent with exactly this. The enclosure or the operating system reads the members' identifying structures to assemble the array; if those have been altered at the start of a member, the set no longer matches what is expected and the volume does not appear. Nothing has happened to the data — the array's contents sit distributed across the members as they always were — but the description that binds them has been disturbed.

Why "no other action taken" is worth so much: because the recoverable version of this case and the difficult version are separated by what happened after the mistake. Accepting the initialise prompt writes a fresh partition structure over the member. Letting the enclosure rebuild or re-create the array writes new array metadata across the set. Reformatting on either platform is worse still. He did none of it, which means the original structures are very likely still present under whatever was written, and the array can be reconstructed rather than carved.

What must not happen now: three things. The array must not be re-created to put it back — that writes the very metadata a reconstruction reads. The enclosure must not be allowed to rebuild or resynchronise. And the members must not be connected to a Windows machine again, including to check.

How it is actually recovered: the members are imaged individually and write-blocked, the array's geometry derived from those images rather than accepted from the enclosure, and the volume reassembled offline from the copies — where no controller can attempt a rebuild and no host can offer to initialise anything. Where a signature or structure was overwritten, the original is reconstructed from the surviving members and the volume's own records.

On the bench

The enclosure was powered down before anything else, since an array that has lost recognition is one automatic rebuild away from a much harder job. The members were removed, labelled by bay, and imaged write-blocked on the Atola TaskForce 2 — every member rather than a sample, because the geometry is derived from the set. The array's parameters were then established from the images by testing candidate layouts against the filesystem's own structures, and the volume reassembled offline from the copies, with anything overwritten at the start of a member reconstructed from what survived. The contents were verified by opening.

The outcome

Every member imaged, the geometry derived and the volume reassembled offline from the copies. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, for anyone who has connected a Mac array to a PC: Windows cannot read Mac filesystems and offers to initialise, which everyone knows to decline — but it may also write a disk signature to the start of an unrecognised disk without asking, and on an array member that region carries the structures identifying it as part of a set; that alone can break recognition while leaving all your data intact; declining the prompt and doing nothing else is exactly right, so do not re-create the array, do not let the enclosure rebuild, and do not connect it to Windows again.

Array accidentally connected to the wrong kind of machine

Power the enclosure down and leave everything else alone — the fact that you took no further action is genuinely the most valuable thing about your situation. Windows can't read Mac filesystems, so it offers to initialise disks it doesn't recognise, and declining that is right. But be aware it may also write a small identifying signature to the start of an unfamiliar disk without asking, and on an array member that's exactly where the structures live that mark it as part of a set — which is enough to stop the array being recognised while every byte of your data is still there. From here, don't re-create the array to put it back, don't let the enclosure rebuild or resynchronise, and don't connect the members to a Windows machine again even to check. Take the disks out and label which bay each came from.

Mac array that met a Windows machine?
Power it down and change nothing else — call Glasgow Data Recovery on 0141 404 0294; members imaged write-blocked, geometry derived from the copies, volume reassembled offline.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.

0141 404 0294