I thought I would share this. I did some testing as I was working with support and for some reason I got the individual keys to work with JAMF's configuration profile without using my own.
For whatever reason, if you select both individual and institutional it will allow you to Escrow the password and also encrypt. The only issue is that it prompts the end user when you log out for the password then shows the decrypt key.
I worked around this by using NoMAD NoLoAD profile that will encrypt on sign in. This completely makes the process seamless at least with an administrator account. I have to do additional testing in my AD environment at work with NoLoAD and a non-admin account, but for the built-in admin account it does allow you to do encryption.
Thought I would share!
Test Machine:
MBP 13 2017
OS: 10.13.4 (17E199)