Background: We currently apply a configuration profile to enforce FileVault, with a personal recovery key and redirection payload. We use DEP and create local user accounts, we're not AD bound or using Jamf connect etc. as yet. We create an admin support account that's hidden
Problems:
1) Approx 20% of our machines don't have encrypted disks. The Policy to apply filefault completes but says, "FileVault is Off.
Deferred enablement appears to be active for user..."
In some of these instances, the same machines are now failing to install updates, e.g. Big Sur 11.2.2 to 11.2.3 - the update requests a password, the user enters the correct password but the password is not accepted - I think this could be related.
2) Supporting users without the hidden local admin account having access to log on can be problematic and prevent troubleshooting. I'd like for our local admin account to be added as a FV user and be able to unlock the disk at first logon.
Any support on t he above two points appreciated.
