Using the FileVault settings via the Config Profile locks out all users from being able to turn off FileVault from the GUI.
Obviously this can be bypassed with disk utility but once it's off and you reboot, the Config Profile should make you turn it back on.
thanks @matt.jamison - just wanted to verify that what you mentioned is what I was also thinking was happening.
I am going to test turning it off FV2 via disk utility and rebooting to see what happens, along with what happens with recovery key.
currently my config profile gets installed, then when current user logs out they are prompted to enter their password to enable them for FV2, computer then reboots (stores key in JSS). This user can press 'cancel' instead of entering their password, but if a different user then logs out they do not get prompted, only they original person that logged out earlier continues to get prompted until they enter their password.
I found out how to bypass this by just having JSS re distribute to all again, and any computer that a user pressed 'cancel' then the current user that logs out will be prompted again. All other computers that already were encrypted will not be affected.
so if user1 canceled and user2 logs out, user2 will not see 'fv2' logout prompt only user1 will until they enter their password. If i have the config re-distribute to all, then if user1 or user2 is currently logged in and then logs out that user will be prompted for password to enable their account for FV2