Skip to main content

i'm using an established policy with JAMF PRO 10.7.1.
i just imaged this Mac mini MOJAVE 10.14 all config and policy are applying excepted FILEVAULT2 using an individual Key stored by JAMF


Did anyone encounter that error?

i also Got error Unknown 76 on the policy failed .


Do you have any configuration profiles installed on that Mac with the top level "FileVault Recovery Key Redirection" payload enabled? That won't work on anything past 10.12.



Can you do a defaults read on the com.apple.FDERecovery plist?


yes i do have a FileVault Recovery Key Redirection" payload enabled and yes its redirecting the key to my MDM.


You need to scope your redirection profile for 10.12 and older and create a new profile to escrow the key in 10.13 and higher. The 10.13 and higher function is located Under Security & Privacy ¬ FileVault using Jamf's built in profiles.


THANKS, is there a some doc i can read more on?


@MACHOUSTON



It's not on the 1st page but here is the non-Apple expert..



https://derflounder.wordpress.com



He has a post about it in detail, you just have to hunt for it...



C


@MACHOUSTON @gachowski Or just search "escrow" at the top of his page. :)
https://derflounder.wordpress.com/2018/01/15/filevault-recovery-key-redirection-profile-changes-in-macos-high-sierra/