Looking for ideas for deploying FileVault 2 enabled devices with AD network users.
I have the following processes at the ready, but support would like it to be easier.
Config Center:
1) New Mac imaged Mac with Casper Imaging - bound to Active Directory, local admin account and a "Temp" standard account created via post imaging script.
2) IT support logs into local admin, manually enables FileVault 2, manually enables Temp account for preboot login.
3) Waits for FV2 encryption to complete, runs Recon to record FV2 status in JSS.
4) Shuts down and device is sent to the end user.
User:
1) Required to call Help Desk for first time setup and only when connected via Ethernet to campus network.
2) User instructed to power on and login to the "Temp" account with password provided by Help Desk.
3) User told to log off, wait for red light to go away (network user availability)
4) Log in with User's Active Directory credentials.
5) Help Desk remotes to user's computer.
a-Sets user's AD mobile account to be an "admin". (requires local admin account to complete, hence the reason to remote over.)
b-Enables users's AD mobile account for FV2 pre boot login within the Security & Privacy system pref. (User is prompted for their password
c-Deletes the "Temp" account
6) Instructs user to restart the computer to help verify they can get past the FV2 pre boot and to their desktop.
Most of the time we don't know who primary owner of the device is before sending it to their department, so we can't pre-populate local accounts or use scripts/policies that assume the first person to log in is the owner. In our environment, the primary user of the device is granted admin rights.
Any suggestions?
(Clients using Mac OS X 10.7.2, JSS is at v8.43)
