Hi;
I'm looking for advise. We have Administrator account created during initial OS configuration but for some reasons passwords for this accounts are unknown. We also have mobile accounts that users are using. All is good but we also have around 100 users with broken security token. Those user are able to login but because of broken security token are not able to disable or enable FileVault. I know that i can reset password for local Administrator account using recovery mode and use this account to remove broken token and grant new token for those users but it would be very difficult to do it for 100 users or much more. I tested this solution and its is working perfectly but still this is a lot of work. Jamf is storing our recovery keys and my question is if it is possible somehow to use recovery key to remove broken token and grant new one ? I was researching google for quite long but no luck.
Or maybe another brilliant idea ?
Regards
Krzysztof
