I had a user working remotely enroll into JSS via the Casper Agent web-enroll. The machine was successfully added to Casper but then an automatic encryption policy kicked off (this has since been disabled and all encryption is done manually.), rebooted as per the policy and she immediately lost access to any local accounts and the encryption policy failed. This makes sense because the machine lost connectivity to Casper after it rebooted because the user was off-site.
To make matters worse, our svcCasperAdmin account has a unique password automatically and randomly-generated. As it stands, the user is only able to see the svcCasperAdmin and Guest accounts when rebooting with no access to the former and no use outside of Safari to the latter.
We were able to procure the recovery FileVault2 encryption key via Casper but because it's last communication/check-in was prior to the encryption, this key is not recognized by the svcCasperAdmin account.
Any ideas on accessing the svcCasperAdmin account or her old, local administrator account prior to encryption?