Hi jamf Nation.
I'm pretty new to jamf and this discussion board is so helpful, thank you so much.
I now have a Problem where I couldn't find a hint here so try to start a new discussion about it.
We are using JSS 9.96, and macOS Sierra 10.12.0
We want to encrypt the Harddrives of all Macs via File Vault2.
I have set up personal + institutional key on jamf and put the start encrypt policy into self server so the user (or at the moment test user) has the chance to decide when he wants to start.
We want to use the logged in user (an AD account) so the user has just to enter his password once and the computer will boot up into is Desktop.
But it will happen that a user forgets his own password (happens really often in the Windows world, so it will be the same in the apple world).
It is no problem to take a look at the recovery key on JSS, and it will unlock the drive without any problems, BUT:
The user is forced to change his password after the boot (no Desktop, only login window) but this is not working. If he is connected to the AD or not, it is not working. (Even when we flag the user in the AD that he has to change the password at the next logon)
Next step was to generate a Master Password (This FileVault.MasterKeychain thing in /Library/Keychains) but the PW reset is also not working with this master password.
It is also not possible to login if I try my last working password (no admin PW change in the AD)
If this is not solvable we have to rethink the encryption options, maybe a special user or not at all.
How do you do that?
Do you have an idea about the problems described above?
Thank you very much
BR
Daniel