Intentionally disable FileVault key escrow?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on
12-07-2016
11:50 AM
- last edited
a month ago
by
kh-richa_mig
After a quick search was not fruitful, is there a way to disable the escrowing of filevault keys while still being able leverage casper to enable FV? My institution has another method in place for escrowing individual keys that we must follow and is currently outside our influence. The security concerns of the keys being escrowed in the jss DB may be unwarranted but again for the foreseeable future must not be kept there without exception.
- Labels:
-
Jamf Pro

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 12-07-2016 03:39 PM
If you have MDM enabled for your computers, you can create a Configuration Profile that will enable FileVault using the Security & Privacy payload. The individual keys won't be captured by the JSS unless you also send down the FileVault Recovery Key Redirection payload. The option under Security & Privacy is in a sub-tab called FileVault. There's a checkbox named Require FileVault 2 that will expand with further options once checked.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 12-11-2016 03:28 AM
@chmp1 the escrowing doesn't happen by default, it's a profile payload called something like "FileVault Key Redirection".
If you have that payload being deployed, stop deploying it.. if you don't have that payload being deployed, then the other system should pick up the keys.
