Has anyone else run across an issue with turning on FileVault for AD accounts in High Sierra? I'm testing deploying now and our workflow is to use MNE to enforce FileVault once the user receives their computer so that on their first login they are prompted to restart. On restart they are prompted for their password, but the Mac gives an error saying to enable FileVault in system Preferences.
So I tried to create a Configuration Profile requiring FileVault and receive the same error.
So I tried enabling in System P{references and receive a different error:
Authentication server refused operation because the current credentials are not authorized for the requested operation.
I found this article: https://support.apple.com/en-us/HT208171 Seems like Apple no longer supports non-admin users or AD users enabling FileVault. This will be a complete PITA for government and enterprise customers and means that we can no longer deploy machines and expect the user to be able to encrypt the drive without intervention from the helpdesk.
