Yo..
We're about to start piloting FileVault, however in addition to the main user being enabled for FV, we also need a management account enabled as well. Yes we can push out a policy to enable it for the management account, but that would expose the account name at the login screen.
So we thought we'd create and use another account called "Recovery"
Aside from setting the policy to run once per user, when setting up the policy, what do you guys recommend to make sure these 2 accounts are enabled for FV at first reboot upon pushing the policy?