I'm new to Jamf, and I've recently inherited a Jamf network of about 200 Macs. My current task is to get Zero Touch Deployment fully functional, so we don't have to do any manual staging on Macs before they are handed to the users. (We are part of Apple's DEP/VPP, and that much works fine.)
tldr; What is the best way to enable FileVault 2 so it deploys automatically, as silently as possible, as soon after initial enrollment as possible?
My goal is to have all of the Macs have FileVault 2 enabled, with the individual encryption recover keys redirected to Jamf server.
I've experimented with both a Configuration Profile, assigned to the PreStage Enrollment, and with a Policy, and both have rough edges that I'm not sure how to smooth out.
There are two specific things that I'd like to remedy:
1) It always pops up and tells the user their recovery key, and cautions them to keep it in a safe place. Is there any way to hide this without resorting to an Institutional Recovery Key? I don't mind users having their recovery key, but I don't like that part of the setup process requires advanced explanation (e.g., you don't need to keep your key, we keep it for you) - I'd rather it be as silent as possible so they don't have to worry about it.
2) When FileVault is deployed as a Configuration Profile and enabled as part of the PreStage Environment, it triggers upon first shutdown. The problem is that it seems the desktop process shuts down before FileVault is finished, so when the final confirmation dialog appears, there is no mouse cursor anymore to click on the dialog; the box is not active, and neither Tab nor Command-Tab work to make it active. Anything you hit on the keyboard just makes the Mac emit an alert sound. The only way I have found to dismiss it is to click around randomly with an invisible cursor until you get lucky and hit the pop-up, then you can hit enter and dismiss it.
I've searched around a fair bit in the docs and Jamf Nation, and haven't found recent discussions/documentation that address my concerns. This doc is the best I have found: https://docs.jamf.com/technical-papers/jamf-pro/administering-filevault-macos/10.7.1/Introduction.html
Any advice on minimizing user confusion when deploying FileVault 2 in a Zero-Touch environment? :)
Thank you!



