Posted on 05-17-2021 12:18 PM
Three of my remote MacOS users with AD accounts are unable to sync their filevault and AD creds. Typically we have users log into the VPN and then change passwords locally in syst prefs. In a couple of cases I have users who can’t seem to authenticate to the domain from their login screens. We have another local account on all our machines that is just a non-admin VPN access account. The current work around is to log in there, get on the VPN and switch user (which only then takes their AD creds). This is a temporary fix and reboots prompt the issue to return. I’ve checked and they both have Secure Token enabled. Is there a good fix for this? I had someone suggest FDESetup commands in Terminal but sounds messy.
Does anyone have a Jamf solution? Or any solution?
Posted on 05-17-2021 01:16 PM
run a policy regulary that updates the preboot settings with the following command:
diskutil apfs updatePreboot /
Posted on 05-17-2021 02:28 PM
Oooh, that looks very simple. I'll test it out! Thanks.
Posted on 02-01-2024 11:40 AM
Did this ever work for you?
Posted on 05-19-2021 11:36 AM
I highly suggest that you start using NoMAD. It's well known that filevault encrypted macs do not mesh with AD. You'll save yourself a lot of headaches.