Hi all.
We are having a Institutional Key infrastructure for our 10.9 clients. At the moment we are in the middle of a project to enable AD binding and logon.
Some of this machines has a local account that is the same as there AD account is.
During the process of binding we are deleting the local account and change permissions for the User folder.
A problem we face is that we, after the first login, want to allow this users to enable themselves as FileVault 2 enabled Users (not all are admins).
What is the best way to do this?
Thanks for suggestions.