We're running a test scenario of a device configured with FDE and passthrough. There's a glaring issue that we can see and that is the the reliance on the Jamf Connect Menu being the only means checking for password mismatches between our IDP and the local account.
The concern is that once credential mismatch is detected a sign in window appears which can simply be ignored indefinitely. With no way to directly enforce IDP and local account password syncs without disabling passthrough which will cause the double login issue on boot and restarts.
Honored Contributor

The recommended configuration of JAMF Connect is to disable FV Passthrough auth. For this very reason among others.