Posted on 10-03-2014 12:15 PM
We have begun encrypting laptops at my job and are using FileVault 2 for the Macs with an institutional encryption key. The recovery key is applied using a Self Service policy. What's happening (or not happening) is that in the computer inventory information FileVault status is showing as Not Encrypted and the Institutional Recovery Key shows Not Present. However, both this statuses are wrong. Any ideas what may be happening?
Solved! Go to Solution.
Posted on 10-03-2014 02:18 PM
How often are the machines checking in for inventory? I've found in my testing of FileVault 2 that it waits for recon to update the FV2 status. I had a machine encrypting and it kept saying "Not Encrypted," then realized inventory was only set to run once a week. Changed that, and the status updated. Maybe try running sudo jamf recon on the machine to see if the status changes.
Posted on 10-03-2014 01:36 PM
I've also seen this behavior. I'm not sure what to make of it either. I have confirmed that the clients are in fact File Vaulted with institutional key, but the JSS returns Not Encrypted. Frustrating.
Posted on 10-03-2014 02:18 PM
How often are the machines checking in for inventory? I've found in my testing of FileVault 2 that it waits for recon to update the FV2 status. I had a machine encrypting and it kept saying "Not Encrypted," then realized inventory was only set to run once a week. Changed that, and the status updated. Maybe try running sudo jamf recon on the machine to see if the status changes.
Posted on 10-06-2014 07:14 AM
Thanks Emily! That was it. For some reason I didn't even have an Update Inventory policy in my JSS. I added it and now we're in business.
Posted on 10-06-2014 07:38 AM
Nice, happy to hear it.
I'm still in the preliminary stages of FV2 testing but so far I've found Casper makes it pretty easy to manage. That and @rtrouton's great research and posts on FV2 on his blog!
Posted on 02-17-2016 01:39 PM
Hi, i get this issue today and i run a Jamf recon command and still no update
i'm on 10.11.3 and JSS 9.82
it has been 3 day's since the encryption was done by a policy.
Help!