Posted on 01-16-2023 11:48 AM
I am noticing that all devices encrypted before manual Enrollment in to JAMF Pro, are missing personal recovery keys. Does anyone know how can I issue a new key to already encrypted devices, bearing in mind encryption happened prior to Jamf enrollment. Thank you :)
Posted on 01-17-2023 05:16 AM
Add the devices to Apple Business Manager and use Automated Device Enrollment. Do it the right way and everything will work.
FileVault needs to be enabled with a configuration profile or have the key redirection configuration profile installed before FV is enabled. Disabling FV and re-enabling FV may work, but you should still be use Automated Device Enrollment if at all possible.
Posted on 01-17-2023 05:20 AM
All our new devices are coming through the method you suggested above. This issue seems to be only with the existing devices which were set up prior to Jamf and hence we have to manually enrol them. If they were to be reset than FV and recovery works fine.
Posted on 01-17-2023 12:41 PM
I have not tested personally, but seems like my predecessor have used the script (found an inactive policy)
https://community.jamf.com/t5/jamf-pro/filevault-indiviual-key-reissue/m-p/242782