Each week we go through and find the machines that have a 'Filevault 2 Individual Key Validation' of 'Unknown' and reach out to those users to resolve (via check in, reboot, etc).
My confusion is why they validations becomes 'Unknown'. I imaged a machine recently and the validation was 'Valid' and everything was fine, but after turning it off for a few days it later became 'Unknown'. What causes Jamf to no longer recognize the key is valid? The machine was imaged and had a valid key then only a day or two later it became 'Unknown'.
Did it try to rotate itself and the new key just needs to be validated by Jamf? If that's the case, how can we change the rotation frequency?
Does it regularly need to check-in with Jamf to validate the key even though it hasn't changed? If so, how can we tell it to validate the key less frequently?
We have a smart group enabled and use the 'Issue new FV key' policy on it but we aren't sure if that's helping at all
Thanks for any insights!
Nate
