Does the fdesetup sync command also work with AD? The documentation only refers to OD which we're phasing out.
FileVault2 - Does sync command work with AD?
Best answer by rich.trouton
fdesetup sync should work with any directory service. One way to verify this should be to add a test account to AD, then add the account to a FileVault 2-encrypted Mac. Once you've verified that the AD account shows up at the FileVault 2 pre-boot login screen, remove the AD account from your AD domain and run fdesetup sync on your test Mac.
Once fdesetup sync has been run, reboot the Mac and see if the test AD account is showing up at the pre-boot login screen. It shouldn't show up, as fdesetup sync should have checked with AD and seen that the account was no longer listed as an account.
Note: The AD account needs to be actually removed from the AD domain. Disabling it will not trigger fdesetup sync to remove it from the pre-boot login screen.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
