Hi,
We are trying to enable encryption on Macs with Casper and found two ways of doing it.
It looks like it can be done either via configuration profile or via a policy. I’ve played with both and it seems that a configuration profile works more consistently. However, if we select the individual key option, which is what we want since we want to manage keys for users, during the encryption process a user is shown their encryption key. If we use a policy instead, the encryption key is not shown (which is what we want). We would use a policy based approach but it seems inconsistent.
What is the best practice in order to enable encryption with an individual recovery key (forwarded to JSS for us to manage)? Is there a way to not show the key to end-users right before the encryption happens? How does everyone have theirs setup?