Hi Everyone,
First post to JAMFNation and fairly new to Casper - we only had our JumpStart in late May '15. Loving the way this community works. :)
On to business.... Our internal security policies require that when an encrypted laptop (Windows or OS have their recovery keys retrieved by an IT analyst, the key must change (generate a replacement) almost straight away. This is so that once the recovery key is used to unlock the laptop it can't be used again so it continues to be secure. This also allows us to track who retrieved the key every time a new one is generated.
I've had a look at the way the JSS manages the FileVault 2 keys. It doesn't appear to generate a new one or track who looked at it.
Is it therefore possible:
1. To have some sort of mechanism that generates a new key after someone looks at the JSS's entry?
2. Audit who looks at it?
Thanks!
Vinny