i'm looking for clarity around filevault and network accounts (not AD!), mostly on big sur and m1 models. until the introduction of silicon macs, i've been using a firmware password to provide some protection on machines that go walking for one reason or another. now with our new m1 macs, it seems that my only option for any kind of hardware security is filevault.
my issue is on shared laptop machines (school setting, laptops are in carts); i don't see a way of enabling filevault while allowing network users to consistently log in without making every potential network user a mobile account and enabling them as a filevault user - which is ridiculous and defeats the purpose of hardware security - if everyone can decrypt the drive, then encryption is worthless.
with filevault enabled, after a reboot, the only user(s) who are able to log in are the filevault enabled users. it would appear my 8021x/scep profile is ignored and i have no network access either (although wpa2 joined networks seem to work?). once i log in/log out of a FV account, network users are able to log in, but in a cart setting, that is hardly reasonable and not at all feasible to have a user log in before everyone else. carts are constantly unplugged, the laptops die, people shut them down or reboot them.
it would seem that my only options are to leave encryption off to enable network users or create a shared FV enabled account that every student logs into.
am i missing something?