Excuse my ignorance…
I have a pilot group for FileVault on some Mavericks MacBooks. I have a couple of questions.
I apparently mistakenly understood that only pre-ordained users could unlock a FileVault encrypted drive. In testing, I find that even a non-admin account holders can access the drive. Is this expected? Have I done something wrong?
It looks like any admin can turn FileVault off on a system. I pushed this out as a configuration profile. How can I prevent my users from disabling it?
