Hi all,
I've got an intermittent problem whereby some macOS devices have a security profile which enables FV2 but when I logout I do not get a password prompt and get taken back to the login screen.
Has anybody else encountered this?
Hi all,
I've got an intermittent problem whereby some macOS devices have a security profile which enables FV2 but when I logout I do not get a password prompt and get taken back to the login screen.
Has anybody else encountered this?
@LewisB I saw that behavior in 10.14 when logging out of a mobile AD account. You could get the FV enable prompt when logging out from a local user, though. But that specific issue seems to have been resolved in 10.14.1.
I should have mentioned this is on 10.14.1 and is definitely a local user rather than mobile AD
I'm seeing he same behavior with our workflow. Works fine on 10.13.6
On 10.14.1 , we get the prompt to enable filevault 2 when logging out, click enable now but it never turns on.
Have seen sporadic "no prompt" at login, logout, and even with check-in.
FV seems like it should be the simplest of the things to implement, but it turns out to be one of the most mind-boggling to get to work reliably. Sometimes ;)
So how do you prompt the user to logout for FV2 then?
We have a policy set to enable file vault at next logon.
So if the user logs out they are prompted to enable filevault the next time they log in.
This is a feature built into Jamf, we didn't write anything custom for this.
@dorellano I have the policy set up as well, but with 10.14 it pops up to enable and yet never actually enables FileVault. Has yours worked with 10.14? My computers are not bound to AD.
@chadsherlock We're using only local accounts. The prompt pop up on 10.14 but it never actually enables filevault.
Seems to work correctly on our 10.13.x machines. Again all local accounts though.
FWIW, only local accounts as well.
Haven't even looked at the AD/JumpCloud accounts for this.
This pretty much outlines the set up here : https://youtu.be/YR-NHVhcxxo?list=PLlxHm_Px-Ie3dNKXGmRIuxFgmiy2KZDH5
@dorellano Yeah I have it set up and works great with anything not 10.14. I am trying to find a solution to turn FileVault on with 10.14 cause the Jamf enable FileVault doesn't actually enable it.
I was told by Jamf to use the Config Profile for FV2 now as the policy method is being fazed out??
@LewisB I just set that up and trying it out. So far on two machines it says "There was a problem enabling FileVault on your computer. Use system Preferences..." I have a case open with Jamf so we will see.
But thank you for the suggestion!!
Can you test with fdesetup enable with -defer on a clean OS install..... I am 99% sure that Jamf use fdesetup when you use the policy... I don't think Jmaf can "fazed out" the policy method as long as the FV profile part is hidden deep in the security profile
C
Who is logged in when the profile is installed, in those cases? The profile, on installation, basically seems to give the same result as running fdesetup enable with deferred mode for the current user at the time.
@alexjdale The user who will own the laptop, the user has a secure token.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.