Currently we use the dual institutional + individual combination, but since all users are local users, the issue persists that sometimes changing the password does not change their filevault password.
We are trying to figure out if using an institutional only key would potentially solve this, but our understanding of the filevault password store is not great.
Maybe this is a dumb question, but If we shifted to an institutional only key, does this eliminate the need for the individual user to unlock FileVault with their password? I guess what I'm asking is whether the individual key causes the password requirement for filevault.
