I ran into this odd issue with a new MacMini (Macmini8,1) with 10.14.3 preinstalled.
I am testing NoMAD with NoMADLogin and I have the first user log in and that creates their account. Jamf Pro then runs a policy to encrypt the device with our institutional key and to add a EFI password lock.
When I boot to the recovery partition, I find that I am unable to disable the EFI password in the Startup Security Utility due to “No administrator was found”. None of the local accounts are listed on the dropdown.
I would think this occurs if the admin account is missing a securetoken but that’s isn’t the case as I was able to encrypt the MacMini.
The only way I can disable the EFI password is to blow the OS away, enroll the device with MDM, then log in as the local admin account that is created during the prestage enrollment. Once I'm in the recovery partition, then the Startup Security Utility usually allows me to disable the password lock with this account.
Has anyone experienced this?