Problems with Filevault Policy during zero touch thin provisioning

rbingham917
New Contributor III

Hello JAMF Nation members. I'm beating my head against a wall with this issue right now, hopefully someone can help out with this.

I've created cascading policies that are triggered by a throwaway account that is created during system setup (Heavy Enterprise, so no Local user accounts, so this guy does his job then gets deleted). This account then signs into Self Service to launch a policy that all it does is kick off a trigger for my first policy, then it kicks off a policy, and so on. Everything is working with the exception of the FileVault encryption job.

The policy is successfully triggered as I see the User Notification message. And it is set to encrypt after 2 logins, since there are in essence 2 accounts that log into the machine. When I look in the logs, it says Filevault is OFF, deferred enablement appears to be active for either the _mbsetupuser or my throw away account.

The only way I have found to get it to work is to flush logs, re-trigger the policy multiple times. If any of you have an idea on what I am doing wrong, that'd be immensely helpful.

Thanks
Robert

0 REPLIES 0