@sanjeewa,
On these encrypted Macs, are you running 10.9.x and are you using the alphanumeric individual recovery key?
The reason I ask is that to enable a new account for FileVault 2, the computer must be running 10.9.x and have an existing, valid individual recovery key that matches the key stored in the JSS.
For more information, I recommend checking out JAMF's white paper on managing FileVault 2 on Mavericks:
http://www.jamfsoftware.com/resources/administering-filevault-2-on-os-x-mavericks-with-the-casper-suite-version-9-2-or-later/
Pretty late to the party, but in case others land here with a similar question:
If I correctly gather what you're asking, you're getting the users to enable FileVault initially, rather than your own management account as the initial enabler of FileVault.
Then you're trying to use a policy to add an additional local admin accounts with the same policy, but getting an error.
Why? Because Casper doesn't know about what the password is to ADD other users to the FileVault encrypted disk. If it had been provisioned with your management account initially, this would work, no problem. But because Casper has no ability to unlock/authenticate to the encrypted drive to add a user, it fails.