Sophos Device Encryption to JAMF Device Encryption Migration

saikat_tripathi
New Contributor II

Hi All,

We are planning to move our device encryption from Sophos to JAMF Device encryption. We have macOS 10.14.6 to 12.4 in our environment. The devices are already encrypted and the recovery key is stored in Sophos. We have configured JAMF Device encryption in JAMF Pro Cloud and the policy. How we can perform this migration seamlessly without having many hiccups and less user interaction where most of our users work remotely. Has anyone performed this, I need some expert opinion about user experience, and seamless deployment before rolling it out.

1 REPLY 1

Jason33
Contributor III

You'll probably want to generate a new Recovery Key and escrow it to Jamf Pro.  Easiest way I'd do this is create a Policy with Disk Encryption payload configured to issue a New Recovery Key, with the type being Individual.  Also create a config profile to your devices with Security & Privacy payload configured for FileVault, and turn on "Escrow Personal Recovery Key".  Test it first to some devices and make sure Jamf captures the key, then use it to unlock your systems.