Up through Catalina I've been enabling FV for the first mobile account
AD user (single user systems) with fdesetup via script using a manually
setup admin that has a secure token and is then removed from the system
after encryption, not sure exactly ...
@S.Puschel, I think you are still mixing terms - Prestage Enrollments
assigns devices from Apple to use Automated enrollment (usually done new
out of box, but not always), URL enrollments prompt the users to approve
trust and install an MDM profile. ...
You used to have to DFU wipe iOS devices on occasion, as some prestage
information would be cached. But it's been a few years since I've had to
deal with iOS. Can't hurt!
@JarvisUno This is the FV section of my user Mobile Account first run
script for 10.15.3. It starts with an Erase+Install package that sets up
ladmin to autologin and trigger DEP enrollment via Jamf Helper, which
binds the machine+misc, never enablin...