One of the things that worried me is data recovery from the Macs with the T2. I saw an article that apple removed the port on the motherboard that allowed them to hook up and recovery data in the stores which only made it seem more unrealistic to be able to recover data.
I finally got some in the lab here and ran it through DEP, created a folder on the desktop, and then finally put a junk text file into the folder to see if I could read it when target booted the machine off a non-T2 machine (in this case a 2016 MBP).
To my amazement the device showed up and I was able to access w/o issue.
Since both machines were signed in with my AD login, I took it to a coworkers 2016 mbp and plugged into their machine and they were able to access the drive and get to the users folder, though not able to get further than that - which is normal.
This begs the question, if the data on the T2s is supposed to be encrypted, how come I can read the drive w/o issue?