Skip to main content
Question

Prompting to enable FileVault

  • April 20, 2016
  • 11 replies
  • 25 views

Forum|alt.badge.img+1

Still getting the prompt to enable filevault encryption on MacBook Pro running Yosemite
after removal of "jamf" ?? Would anyone know what is the cause and how to remove ??

11 replies

Forum|alt.badge.img+11
  • Contributor
  • 225 replies
  • April 21, 2016

How did you "remove jamf" from the machine.. Did you remove framework from the terminal, and also removed out of JSS?


gskibum
Forum|alt.badge.img+13
  • Valued Contributor
  • 288 replies
  • April 21, 2016

I had the same issue for several months, both with Yosemite and El Capitan.

The 10.11.4 update solved it for me.


Forum|alt.badge.img+16
  • Honored Contributor
  • 1054 replies
  • April 21, 2016

Yep there is a thread about this floating around or in a thread about FV... it was sort of left as an Apple issue..

C


Forum|alt.badge.img+15
  • Contributor
  • 589 replies
  • April 21, 2016

That's because the Mac is set to enable FileVault. Removing JAMF doesn't remove that command. I believe 'fdesetup disable' will cancel it though.


gskibum
Forum|alt.badge.img+13
  • Valued Contributor
  • 288 replies
  • April 21, 2016

fdestup -disable would only work short term for me. The only permanent solution I have found is 10.11.4.


Forum|alt.badge.img+11
  • Contributor
  • 225 replies
  • April 22, 2016

I have yet to experience that issue... Normally if I unenroll a machine and remove from the JSS, they wouldn't get the policies for FileVault2..


gskibum
Forum|alt.badge.img+13
  • Valued Contributor
  • 288 replies
  • April 22, 2016

@JustDeWon

Yeah at first I also thought it was a Casper thing. But I would remove the JAMF framework and also remove the devices from the JSS, and would still get the prompt.

I have a test box with a small SSD (i.e. fast encryption) I can test this with. I've been meaning to confirm my findings anyway. This drove me nuts for quite some time.


Forum|alt.badge.img+5
  • New Contributor
  • 7 replies
  • April 25, 2016

try hosing the /Library/Preferences/com.apple.fdesetup.plist (if there is one). I think @thoule & I figured out at some point it was being a PITA.


gskibum
Forum|alt.badge.img+13
  • Valued Contributor
  • 288 replies
  • April 25, 2016

OK so I did my little test and threw in @themonger13's suggestion into the mix.

  1. Lay down 10.10.5 Yosemite & create local admin accountl.
  2. Enroll in JSS. A hidden management account is created on enrollment.
  3. Scope FiveVault2 via policy in Self Service to this box.
  4. Recon (for no good reason).
  5. Remove Mac from JSS.
  6. Remove framework.
  7. Disable FileVault2 and let decryption process complete.
  8. Reboot and log in to local admin account - and get prompted to reenable FileVault2 (without a second account to log in to it would be necessary to reenable FileVault2).
  9. Cancel and return to login screen.
  10. Log in to invisible management account. No prompt.

  11. Delete /Library/Preferences/com.apple.fdesetup.plist.

  12. Reboot and log in to local admin account - no prompt for FileVault.

It seems @themonger13's suggestion works.

Press on to confirm whether or not El Capitan 10.11.4 corrects the problem:

  1. From the original local admin account reenable FV2 via Self Service.
  2. Let encryption complete.
  3. Disable FV2 and let decryption complete.
  4. Reboot.
  5. Log in to original local admin account and again get prompted to reenable FV2.
  6. Deny and log in to second local admin account.
  7. Confirm /Library/Preferences/com.apple.fdesetup.plist is present.
  8. Upgrade to El Capitan 10.11.4 through Self Service.
  9. Attempt to log in to first local admin account - get the steenking prompt. So much for the 10.11.4 solution.
  10. Log in to second local admin account and delete /Library/Preferences/com.apple.fdesetup.plist.

  11. Problem gone.

@themonger13 wins the beers.


mscottblake
Forum|alt.badge.img+24
  • Honored Contributor
  • 341 replies
  • April 26, 2016

The underlying reason is that Casper just initiates the change. Once it's set to enable, the rest is internal to the OS. You have to remove the plist to tell the OS to no longer enable.


Forum|alt.badge.img+4
  • Contributor
  • 14 replies
  • April 26, 2016

If you're buyin' @themonger13 likes this