Does anyone have a tried and true process for enabling FileVault during enrollment?
Our Mac's have been "out in the wild" for a few years, we've been slowly getting them all enrolled in JAMF. We initially enrolled most of the population w/o FileVault enabled (bad idea). We've since gotten most of them set up with FileVault with the recovery key escrowed in JAMF.
Anyway, now I am looking for a good method of enabling FileVault duing the enrollment process for new Mac users or stragglers who have not yet enrolled. I have a policy set up for FileVault, with the FileVault configuration payload set up. Set up for require at next log out, triggered for enrollment complete. Seems like it should work.
Problem that I am seeing is, it doesnt seem to run properly. Logs state: Deferred enablement appears to be active for user 'johndoe'
FileVault never seems to kick off...
We've been monkeying around with FileVault enforcement for a while, so I assume that's why.. just wondering if there's a way to fix this?
Thanks!
Ben