I've run into an odd issue with Filevault2 Encryption. The setup is as follows:
OS 10.11.6
Accounts are all Local (No AD or LDAP integration)
Encryption Policy is deployed via the JSS
Personal Encryption Key's
The system is encrypted when the admin user logs in. This account has no issues logging in. When a second "NON-Admin/Standard" user account is created or if an existing standard user is added to encryption via the system prefs. The user can successfully login to the Encryption Login screen, they are prompted to login to a second screen. Account login at the second screen fails. There is no error message (that I have found).
Here is the rub. If you login with the regular admin account and then make the Standard user an Admin, they can log all the way through to the desktop without being prompted for a second password. Change the account back to a Standard User and they cannot login again (at the second Window).
This sounds like a permission issue to me. The standard user is unable to access something that the admin user is able to access. Any ideas what?
My only attempts to resolve include removing and re-adding the user via FDESetup and logging in as the account that fails and running fdesetup sync. I have been able to re-create the issue on 3 systems. Any ideas/help would be appreciated.
Thanks,
Jasen