Hello everyone,
Occasionally, we have a Mac enroll with an unknown or invalid FIleVault 2 recovery key (an example is when a Mac is encrypted before MDM enrollment). We currently use a script that prompts the user for their password, and then rotates and re-archives the key.
Script: https://github.com/homebysix/jss-filevault-reissue
I have just learned that in Catalina, Apple has removed the ability to pass the username/password to the fdesetup tool. The script notes this at the bottom of the page: "This script will not work on macOS Catalina due to the inability to pass user authentication information to the fdesetup tool."
Does anyone have a solution to ensure the FileVault2 recovery key is escrowed to the JSS in Catalina?
