Hi,
I'm all out of ideas and need some serious help! Please excuse the length of this post but I needed to add all the details.
So we are moving to JAMF connect and it works perfectly!! The machines in DEP pull down all the policies and once done the device sits at the shiny JAMF connect SSO page ready for the user to log in. They log in, DEPNotify installs a few apps, filevault runs for them, and the world is a happy place!
My issue is non-dep machines.
This still requires an engineer to kick off a quick add package and in doing this it kicks off the normal enrolment policies. Doing this runs filevault and so it grants the admin account the secure token and encrypts the machine to them.
After this the mac cannot be shipped to the end user as it will be locked to the admin account. The way round this was to get the user to log in with the engineer but during these times theres a massive push to remove this engineer intervention and go "zero-ish" touch.
I've tried cancelling the encryption but then the mac is stuck in deferred mode and nothing can be encrypted.
We have a self service policy to grant the user a secure token and add them to filevault and this works perfectly, but, again we cant use this as the machine would have already been locked to the admin account and the end user wouldn't be able to even log in.
I need something that removes the deferred encryption for the admin account and basically kicks off when the new user logs in.
I've tried using Outset to kick off the encryption policy but it doesn't seem to work anymore (or I cant get it to work).
I'd love to know how people have got round this if they are in the same situation?
