I have computers which are FV2 encrypted but don't show up in the smart group we created. We even had one system leave the group when upgrading from 10.10.0 to 10.10.1
I don't think it's a Yosemite issue though as we have Mavericks systems that are also not being included.
The criteria which only finds 30 out of 39 systems is:
FileVault 2 Status is Boot Partitions Encrypted
The criteria which finds the 39 systems is:
FileVault 2 Status is Boot Partitions Encrypted
or FileVault 2 Recovery Key Type is Only Individual
or FileVault 2 Recovery Key Type is Only Institutional
What's odd is if I have the criteria set only to
FileVault 2 Recovery Key Type is Only Individual
or FileVault 2 Recovery Key Type is Only Institutional
It picks up even more systems, ones which aren't encrypted, so why would it see that the key was present.
I've heard murmurings of Smart Group bugs but haven't read anything recently. I'm running JSS 9.6.29507.c JAMF hosted.