I'm having an issue where during PreStage enrollment I have an admin account created for temporary purposes to get computers setup for a users. After the setup process is done, we delete the account. I'm encountering an issue where on some computers, I'm not able to delete the admin account. After trying multiple methods (Jamf policy, Jamf Remote, jamf binary, and sysadminctl), I am still unsuccessful. What I've found is that when I use the sysadminctl command to remove the account, I'm presented with the following error:
"<useraccount> can not be deleted (it's either last admin user or last secure token user neither of which can be deleted)
When I use the "fdesetup status" command, FileVault is turned off. When I look at the computer record in Jamf under Inventory > Disk Encryption, I see the account that I can't delete listed under "FileVault 2 Enabled Users:" which in my view doesn't make sense
I suspect because it's listed in Jamf as an enabled user there, this is the cause of the issue but I'm not sure how to confirm that and resolve that. This happening on over 20 computers so manually going to each one to delete is less than ideal.