We are having a terrible time with filevault and want to find out if there was some kind of definitive guide to its implementation. Right now we are binding and using AD accounts (Implementing Connect in 2024. Would love to hear if this would help our situation) to login. When a user changes their password it seems like we need to disable filevault, to reset the password and then reenable filevault otherwise the changing the password through system prefs doesn’t work. And end users can’t disable filevault this because they aren’t local administrators.
Questions and issues I have:
Are we supposed to use a policy or a configuration profile in Jamf Pro to enable it? Pros and cons?
We have shared Macbooks that we need to be able to logged into by new users on a regular basis. How do we enable that new user to automatically get access to a filevault encrypted drive? Based on this should we be using an institutional key or a personal key, or does that not even matter?
What is the impact if any if we turn on filevault from system preferences while we are delivering a new device to a new user. Will Jamf Pro still try to escrow the key? If not, is there a script to force that to happen?
How are we supposed to update filevault when a user changes their password? Is there any difference if you are using AD accounts on a bound device vs using local accounts with Jamf Connect?
