Jamf Nation,
Been troubleshooting FV2 on our High Sierra build for a bit now. I understand how to enable/disable a secureToken, that an account can only get a token using setup assistant and what the sysadminctl command can do etc.
What I want to know can be broken down in two questions...
1. Does an administrator have to be secureToken "enabled" at all times, or once secureTokens are assigned can we disable? Or, can the administrator be secureToken enabled.... but somehow not be enabled as a FV2 boot screen login account?
which leads me to my next question/issue...
2. We want to be able to see 2 users on our FV2 boot screen, one would be our Standard Users account and the other would be a generic "Standard" user account for our IT support. We do not want our admin account on the FV2 boot screen.
I cannot figure out how we can accomplish this simply. I have tried giving temporary admin rights to the generic account and removing rights from the admin accounts for encryption purposes. However, upon changing those rights back, I see the admin account in the FV2 boot screen.
I am going to try revoking rights from admin and having a user with admin rights encrypt the device. This way only the user will be at the FV2 boot screen. After that I will promote rights to the admin account and see if it appears at the FV2 boot screen. Of course I will have to "Enable" the generic user for FV2 boot screen. But if this works, its only going to help a user with admin rights and I am still stuck on standard users.