I am testing a reset local user password Policy in case a user forgets his macbook login password. I see this as a trigger option:
What kind of script would I need?
Best answer by Tribruin
PRK = Personal Recovery Key or, sometimes known as FileVault Recovery Key. If you have FileVault enabled, then you will not be able to rotate the user's password. When you boot the computer, the computer boots to a pre-OS environment to unlock the drive. The user's password is used to unlock the drive. Until the drive is unlocked and the O/S is booted, it is unable to receive MDM command. So, by deduction, If the user forgets their password, you won't be able to reset it using Jamf.
So, instead you need a work flow that utilizes the PRK to reset the user's password. Hopefully you are escrowing the PRK in to Jamf. If a user forgets their password, they would need to follow these steps:
Boot to recovery
Unlock the drive using the FileVault PRK
Reset the user's password
Reboot the computer and login using the new password.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
