Hi, I need some help on this.
We would like to finally make the step to a truly zero touch workflow.
We hav a PreStage which successfully creates a local admin and a local (standrad-) user as shown below.
Now with macOS Big Sur the standard user gets a secure token and is therefore granted to initiate the FileVault encryption. Great. But the local admin doesn't get a secure token and therefore is not allowed to unlock FileVault.
From my research the localAdmin would automatically get a secure token as I would log in through the login window but in truly zero touch this may never happen and if the user returns the Mac we wouldn't be able to unlock it.
Has someone a solution on how to grant the localAdmin a secure token by script?
