Skip to main content
Question

10.13.2 Cannot enable filevault with AD account?

  • December 8, 2017
  • 11 replies
  • 42 views

Forum|alt.badge.img+3

We just received a new macbook and we enable filevault with AD admin account. When I try to do it now, I receive the following message. How can I resolve this issue?

"Authentication server refused operation because the current credentials are not authorized for the requested operation."

11 replies

scottb
Forum|alt.badge.img+18
  • Valued Contributor
  • December 8, 2017

Interesting, based on the release notes and a message from a colleague that it's now working for him.
I have not myself tested, but have a look.

Release notes:

If you change your Active Directory user password outside of Users & Groups preferences, the new password can now be used to unlock your FileVault volume (previously, only the old password would unlock the volume).

macOS 10.13.2


Forum|alt.badge.img+7
  • Contributor
  • December 8, 2017

Pretty bold for Apple to say that when it appears it only works when you manually run diskutil apfs updatePreboot / after the user's password is changed. Otherwise, FV2 will continue using the original password. Hooray, another unusable version of 10.13!


scottb
Forum|alt.badge.img+18
  • Valued Contributor
  • December 8, 2017

@doggles -you'll like this then...
High Anxiety, er, Sierra...


Forum|alt.badge.img+7
  • Contributor
  • December 9, 2017

@scottb im digging the marshmallow analogy


Forum|alt.badge.img+9
  • Valued Contributor
  • December 11, 2017

@doggles Explains why policies that create users that should be added to filevault are not and there is an error when adding to FV. Started on 10.13.2


Forum|alt.badge.img+9
  • Valued Contributor
  • December 11, 2017

Policies that do an authenticated restart with FV do not reboot the computer under 10.13.2 in our environment. Noticed on a 10.13.2 system and confirmed there. Had a 10.13.1 system run the policy and it rebooted. Had that same computer update to 10.13.2 and run the policy; result: no reboot occurred.


Forum|alt.badge.img+17
  • Valued Contributor
  • December 11, 2017

Yes, I opened a ticket about this with Apple - please do the same if you're able! They do not have an ETA for a fix yet, so I'd love some more pressure on it. They knew about the issue and sort of vaguely alluded to it being a bug, so we'll see.


Forum|alt.badge.img+1
  • New Contributor
  • January 2, 2018

Anyone have any updates on this?


Forum|alt.badge.img+9
  • Valued Contributor
  • January 31, 2018

On 10.13.3, I can't speak to enabling fv yet, but FV authenticated reboots via jamf are still broken, which says to me the underlying issue around FV has not yet been fixed.


Forum|alt.badge.img+1
  • New Contributor
  • February 22, 2018

Hi,

Maybe this will help - https://community.sophos.com/kb/en-us/128052


Forum|alt.badge.img+9
  • Valued Contributor
  • April 10, 2018

Everything still broken on 10.13.4+JSS Pro 10.3.1.