Our FileVault 2 encryption policy is scoped to devices that are not already encrypted, however it seems that the new MacBook Pros (and possibly iMac Pros, but we don't have any to test) are being seen by Jamf as already encrypted, even when FileVault is off. I suspect this is because the disk is, technically, already encrypted by the T2 chip hardware. While this would prevent the drive from being accessed if removed from the computer, without FileVault also enabled it doesn't prevent the disk from being unlocked without a password while still inside the machine. Apple certainly recommends enabling FileVault, even on T2-capable Macs:
https://support.apple.com/en-us/HT208344
Anyone else have a workaround for this, to get T2-equipped Macs with FileVault disabled to be seen by Jamf as unencrypted?
