Skip to main content
Question

FileVault 2 Deferred Enablement - El Capitan

  • October 7, 2015
  • 34 replies
  • 149 views

Show first post

34 replies

Forum|alt.badge.img+16
  • Honored Contributor
  • December 3, 2015

Deferred next log in doesn't work, and it's the only way of setting FV2 that I know of that they user can't override/skip.

When the deferred is set to next log in, after the user logs in they get a popup and if the user select continue instead of ok the machine will reboot automatically back to the same window. Also set to next log in the user doesn't get the popup of the recovery key. Making it impossible for the user a disable FV2 or use the mac not encrypted, from what I can tell. Allow us to deploy Macs with very very limited staff interaction, or zero touch.

With it set to next log out, the user can just select continue and the Mac will not be encrypted and if they do select ok the will see the FV2 key.

C


Forum|alt.badge.img+15
  • Contributor
  • December 3, 2015

Yeah, but that's a workflow question in this case more so than a technical one. In our case, our provisioners won't hand a Mac to a user until FV is enabled, so that workflow works for us.

But, my point is that it works at all. "At next login" definitely does not currently work in El Capitan at all. So, if you have a FV requirement now, "at next logout" will work though you may need to adjust your workflow.


Forum|alt.badge.img+5
  • Contributor
  • December 3, 2015

I did find that thread previously and changed it to 'At next logout'. The prompt does pop up with the password request but I get "There was a problem enabling FileVault on your computer. You should use System Preferences Security & Privacy to view or change FileVault". Don't know why this is happening. Will have to look in the logs.


Forum|alt.badge.img+5
  • Contributor
  • December 3, 2015

Getting ManagedClient[xxxx]: MCX.doCmdLogout: setupFileVaultFDE enable returned 11 which is an authentication error. Strange...Oh well, at least I'm getting prompted now.


Forum|alt.badge.img+15
  • Contributor
  • December 3, 2015

(Disregard.)


Forum|alt.badge.img+15
  • Contributor
  • December 4, 2015

@Vitamin-Z Hmmm, that error I haven't seen before. A few questions that pop into mind are... Are your users admins? What is the trigger for the policy itself? JSS 9.81 right? Is the policy scoped to all users?

I don't know if some of those questions are relevant or not, but they're the first variables that come to mind.


Forum|alt.badge.img+5
  • Contributor
  • December 4, 2015

@bmarks Yes, my users are admins. The trigger is 'Recurring Check-in'. We are on 9.81. Currently as a test, my Mac is the only one.


Forum|alt.badge.img+8
  • Contributor
  • December 8, 2015

10.11.2 is out - downloading now to make sure this build maintains our happiness :)


Forum|alt.badge.img+14
  • Contributor
  • December 8, 2015

Seems back to normal. AD ... I just can't quit you no matter how many hints Apple gives. :)