Skip to main content
Solved

FileVault 2 Not Enabling "Deferred enablement appears to be active for user..." - Has Secure Token

  • September 7, 2023
  • 4 replies
  • 38 views

Forum|alt.badge.img+4

I have combed through all the threads here before posting, I am trying to figure out why this is happening to all unencrypted Macs on this server. The user gets a pop-up to enable FV, enter password, and then the following shows up in the logs:

 

All the users have Secure Token, and they are enabled for FV2. Any help would be appreciated. 

 

Here is the setup we have:

 

 

 

 

Best answer by sdagley

@BrookieB Has the user logged out and back in again (or restarted)? Once enabled FileVault won't be activated until that  happens.

4 replies

sdagley
Forum|alt.badge.img+25
  • Jamf Heroes
  • Answer
  • September 7, 2023

@BrookieB Has the user logged out and back in again (or restarted)? Once enabled FileVault won't be activated until that  happens.


Forum|alt.badge.img+19
  • Honored Contributor
  • September 7, 2023

Just a recommendation. You don't need a policy and profile anymore. Just push the profile to the computer. If you are using a PreStage enrollment, include the profile in your PreStage and ensure it is scoped to stay on the computer after enrollment. That will ensure FV is enabled when the user first logs in. 


Forum|alt.badge.img+4
  • Author
  • New Contributor
  • September 12, 2023

Just a recommendation. You don't need a policy and profile anymore. Just push the profile to the computer. If you are using a PreStage enrollment, include the profile in your PreStage and ensure it is scoped to stay on the computer after enrollment. That will ensure FV is enabled when the user first logs in. 


Thank you! I will try that out. 


Forum|alt.badge.img+4
  • Author
  • New Contributor
  • September 12, 2023

@BrookieB Has the user logged out and back in again (or restarted)? Once enabled FileVault won't be activated until that  happens.


I think this might be it. The list is SLOWLY going down, and the remainders have not rebooted in a month+, before I created the policy!