We currently have JSS set up so that a local admin account is made on all machines at enrollment. We also have a log in configuration profile set to Username and Password text fields, and have fast switching disabled (unclear to me if this is causing the issue or not). We have FV2 encryption enabled on all machines as well. Unfortunately, it came to my attention today that if a user does anything OTHER than logging out via the Apple menu, then when you try to unlock the machine, you are not able to try logging in as a different user (aka the management account that I want to be able to access their machine with). Any thoughts on how to get around this?
My knee jerk is to try using a policy to force a log out when a user shuts off their machine, but I'm not sure this would work when you just hold the power button to turn off the machine. Another thought would be adding the local admin that management uses as a FV2 enabled user? I've been doing some digging on this, but shy of manually going to each Apple machine and logging in on the management account to trigger FV2, I'm not sure how to achieve this.