Hey everyone,
We're currently in the POC phase with Jamf, and there's something that's really bugging me. We tried Kandji before, and their FileVault solution is way better than Jamf's. With Kandji, you just set up the profile, assign it to a Blueprint, and if FileVault is already enabled, it prompts the user to enter their password, rotates the key, and escrows it to their server. If FileVault isn't enabled, it forces the user to log off to enable FileVault and escrow the key. But with Jamf... it's not as simple as creating the config profile.
For machines that already have FileVault enabled, we had to set up EscrowBuddy. The instructions were clear, but now we have 10 devices enrolled and 8 of them haven't escrowed their FileVault2 key to the Jamf server. This could go on forever because there doesn't seem to be an integrated solution (I couldn't find one in the options or this forum) that forces the user to log off.
Does anyone have experience with this or know how to tackle the logoff issue? Thanks!