I'm working on a client setup right now where the computer goes through ADE/DEP and a tech logs in as the administrator account.
That kicks off the DEPNotify Helper script and that workflow. This includes the naming of the computer which, in turn, scopes the FileVault Configuration Profile to the computer. It also includes binding the computer to AD.
At this point, if I check fdesetup for a list of enabled users, I just get the admin account. So far, so good.
After that the admin logs out (but doesn't reboot or shut down or other wise go back to the FileVault lock screen) and a staff person logs in which creates the mobile account. Now if I run fdesetup I see the admin account and the staff account are both enabled. Jamf confirms the same thing. Both accounts are enabled and FileVault is turned on at this point.
However... if I reboot, only the admin account is visible on the lock screen.
If I don't reboot, but instead log in as either the staff account or the admin account again and just log back out, when I reboot both users are there.
I'm trying to make the setup process easier, not more tedious. Is there a way to get macOS (Sonoma 14.4+ on Intel for this test) to update the lock screen without these extra steps? I would have bet good money that when the mobile account gets listed as FileVault Enabled that it would also get added to the lock screen.