Once the supplemental 10.13.2 upgrade is installed, I could no longer
add AD users to File Vault. The issue seems to be Secure token is not
enabled for AD users the following fixes the issue Sysadminctl
interactive -secureTokenOn -password Check
wi...