Hi,
I am evaluating the product at the moment and have a few questions around this...
- If a user has enabled filevault previously and only enabled their own user account as a FV2 user can I get Casper to remediate this by either enabling the admin account as a FV2 user or capturing the existing recovery key?
- If I wish to deploy a local admin account to all Macs for technicians to use how can I ensure that this account is enabled for FV2 on all machines? In the Windows world we don't use local admin accounts at all as the TPM based encryption still allows the system to boot without needing a password. This seems like it might be tricky to manage as the usual procedure is that technicians are in an admin AD group and so can log on as an admin but as we can't pre-enable all of them as FV2 users they wouldn't be able to logon if the system owner wasn't around.
- Am I asking for trouble and would it be better to decrypt existing encrypted machines and let Casper handle it from start to finish?
Thanks
