Our historical setup of new Macs:
1. take the mac out of the box
2. netboot and run Jamf Imaging which block copies a preconfigured hard drive image that already has a local admin account and enrolls in our JSS automatically and creates a hidden management account
3. after first reboot, many apps install as part of the post-imaging process
4. I run a Self Service policy that enables FileVault with an institutional key that enables the management account for FV.
5. Reboot and let the drive encrypt in less than 1 hour.
Yes, I know "imaging is dead" beginning with High Sierra. I took a 2017 MBP out of the box today and decided to try the new long & painful way Apple is forcing us to use.
1. Took mac out of the box and turned it on
2. created the standard local admin account that must be present on the machines
3. manually configured ssh, Remote Management, and all the other things that need to be configured in the admin account.
4. copied a QuickAdd.pkg from our 10.7.1 JSS to the desktop.
5. Ran the QuickAdd.pkg and let it enroll in JSS and install apps and run all the same post-imaging policies
6. Ran the Self Service Policy that enables FileVault. IT FAILED. The error was basically that the management account doesn't have a secure token.
7. I tried changing the Encryption setting to enable the current (local admin) account. That failed with some kind of authentication error.
9. I dug around on the internet until I found the sysadminctl command i needed to run to enable secure token on the management account.
9. ran the Self Service Policy again and it finally seemed to take.
10. Rebooted and just got the standard ID & PW box... not the FileVault account icons to pick from. I logged in as the local admin
11. I was presented with a dialog telling me that filevault is being enabled.
12. I get to the desktop, launch Terminal and run fdesetup status and it says "Encryption in progress: Percent complete = 10"
13. I waited 15 minutes and run fdesetup status again and it is STILL at 10%
14. I went to System Preferences > Security > Filevault and the estimated time is 2 DAYS!!!
15. After another 20 minutes, I rebooted. This time i was presented with the FileVault login with the icons for both the local admin and the management account.
16, fdesetup status only says 15% now, but System Prefs> Security >filevault still says 2 DAYS!
I have to deploy this computer in a few hours. I am not permitted to deploy any computers that are not fully encrypted. Is this the new reality? How is this new reality supposed to make our lives any better? Is there a step I'm missing? Am I doing something wrong? Adding the local admin account to FV is absolute. I am willing to give up on adding the management account, but I can't figure out how to make the FileVault policy apply to the local admin (it DOES have a secure token).