I'm working to get FileVault 2 encryption enabled on all laptops. I’ve gotten FV2 JSS policies working and all seems to be going well. The plan is to have users run a self service policy to enable FileVault 2 encrytion. That policy uses the a Disk Encryption config to apply the “Institutional And Individual” recovery key.
I am a little confused about administering FV computers. Users are creatives/professionals typically with an assigned machine. We currently run 10.9.5, and have a local admin account on the machine as well as an admin account created for casper. Users are all active directory accounts.
While laptops are typically assigned to a single user, there are times when I need to get into a laptop for admin purposes. if I’ve only added the main user as a FileVault2 account (+institutional), I’ll have a bit longer of a process (go to jss, get individual recovery key, unlock using Individual’s Key, or use institutional key) to gain access to the machine if it's FV2 locked.
If I add a local admin account, it shows at the FV2 unlock. Plus I’m not sure of what considerations there are with having a local admin account enabled for FV2.
Does anyone care to weigh in on the pro’s/cons of having a local admin account enabled for FV2 in addition to the primary user(s)?