My understanding is that all a policy to deploy an "encryption
configuration" is that it configures FileVault 2 deferred enablement via
fdsetup. If you want to check that the policy is working as expected (at
login), run: host:~ user$ sudo fdesetup s...