We’re migrating Macs from our old JSS to a new JSS. The Macs in the old JSS are encrypted via FileVault 2. There are preexisting Macs in the new JSS that are also encrypted.
Since the FileVault 2 policy in the new environment is set for all computers and users with an ongoing frequency, what is the best way to generate new keys for the migrating Macs (keys are redirected to the JSS via top-level policy)?
I do see policy for ‘Disk Encryption - Issue New Recovery Key’, but doubt that this policy should also run alongside the FileVault 2 policy.
I think a Smart Computer Group might help, but its criteria is allusive.
Does anyone have any advice? It’s appreciated!