We are going to be turning over our 1500 device fleet to M1 Airs this summer and since there is no more EFI passwords, we want to restrict users from being able to enter recovery mode and restrict them from entering DFU mode. It looks like enabling FileVault 2 is the path to this goal but there doesn’t seem to be a clear set of guidelines to accomplish this. We want to be able to have one passcode or one account as the FileVault enabled user but Jamf says we can’t use a management account if it is an account created by Jamf Pro? So it sounds like we would have to manually create the same account on every machine in order to accomplish this? In addition, we want to make the restore process as easy as possible since we will have to refresh 1500 devices every summer. Does anyone have some advice on where to start with this? The first batch of computers going out are staff and we aren’t as worried but we can’t give the laptops to students without more security protections on them than they have now.
Question
Protecting M1 with no more EFI security available
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
