I have some questions about FileVault.
Let’s say you have a new Mac computer that is installed with Jamf DEP. During the process a local admin account is created. And the computer will be bind to Active Directory. Then the device is given to the user who logs in onsite with their Active Directory credentials which creates a mobile account. Now he can login with his mobile account of course also from offsite.
The Filevault configuration profile is installed and when the user logs out FileVault will be enabled. So far so good. But let’s say somebody else from AD wants to log into the computer now with their AD credentials. This would not work right? Because the “new” user cannot even unlock Filevault before the boot process
What about the mobile accounts and unlocking FileVault. Will it work? Or do mobile accounts need to be on VPN or Onsite to reach ldap ??

