I apologize if this has already been discussed. I have searched through the discussions and haven't really found anything similar to the issue that I am trying to resolve/prevent. I know in the long run, removing admin permissions for end users will prevent this from happening but we as an organization are not there just yet.
My organization is in the healthcare industry and we are required to follow HIPAA regulations as well as policies implemented by our InfoSec department. It is my job to enforce those regulations and policies. For the most part all of our Macs do have FileVault enabled and they are encrypted. However, we have a few resistant end users that have a little to much knowledge of the Mac OS and have turned on deferred enablement which is preventing Jamf from enforcing encryption. I am wondering;
Is there a way to have a policy to deactivate the deferred enablement if a user does go into terminal and enables it?
Other than removing admin rights, is there a way to prevent a user from re-enabling it after it is disabled and encryption begins?
Any ideas would be greatly appreciated.

