Following an upgrade to our JSS, a Filevault policy was pushed down to a bunch of machines that shouldn't have it. Now, after every log out or restart they are asking for a password to enable filevault. I have removed them from the policy but they are still trying to enable filevault. Is there any way to remove the policy from the machines and stop this from happening?
Solved
HELP! Policy Question
Best answer by mm2270
Yes, target the machines with another policy that runs:
fdesetup disable
While you might think that command would only turn off FileVault if it's already on, it actually works to remove the deferred enablement process as well. Try it on one of the Macs that's trying to enable FileVault (use sudo when running directly in Terminal) and then log out.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
