Skip to main content
Solved

FileVault 2 Smart Group Problem

  • December 1, 2021
  • 2 replies
  • 15 views

Forum|alt.badge.img+5

Hey,

I have a problem in my environment where I have a Smart Group ("FileVault Eligible Devices") set up according to best practice. (https://docs.jamf.com/technical-papers/jamf-pro/administering-filevault-macos/10.30.0/Creating_Smart_Computer_Groups_for_FileVault.html)

FileVault 2 Eligibility Is Eligible

AND

FileVault 2 Partition Encryption State Is Not Encrypted

Just like it states.

 

My problem is, however, that devices that already have FileVault enabled get put into this group. Now I no longer know which devices had FileVault enabled by JSS and which had it enabled prior to enrollment. (Most of the devices either report PRK as unknown/invalid or report encryption state as Unencrypted despite being encrypted, even FileVault enabled by JSS.)

 

I have created a Ticket to Jamf support about this, they elevated it to their Tier 2 team but they stopped responding to me. Could someone here have any insight?

 

Thanks!

Best answer by user-qHFlIsdGUC

This works with inversed logic: 

"FileVault 2 Partition Encryption State" "Is" "Not Encrypted" -->

"FileVault 2 Partition Encryption State" "Is Not" "Encrypted"

2 replies

Forum|alt.badge.img+5
  • Author
  • New Contributor
  • Answer
  • December 3, 2021

This works with inversed logic: 

"FileVault 2 Partition Encryption State" "Is" "Not Encrypted" -->

"FileVault 2 Partition Encryption State" "Is Not" "Encrypted"


Forum|alt.badge.img
  • New Contributor
  • December 6, 2021

This works with inversed logic: 

"FileVault 2 Partition Encryption State" "Is" "Not Encrypted" -->

"FileVault 2 Partition Encryption State" "Is Not" "Encrypted"


Thank you for replying with the solution - I had the exact same problem and had referenced the same documentation.