Hi and welcome to this special page which I created in support of my JNUC 2020 presentation.
Apart from the demo I promised you, I’ll link some resources which may help you in Managing FileVault on macOS Catalina with Jamf Pro. Depending potential questions during the session, I may add additional links or comments on the go.
JNUC 2020 Presentation
NOTE: If you have any questions which were not answered during the Q&A in the session, feel free to add them in the comments below!
Demo Video
A quick demo of some of the Terminal commands and workflows discussed during the session:
Some links to useful resources
Blogposts related to FileVault on this Blog:
https://travellingtechguy.blog/?s=filevault
Script to grab a good overview of the FileVault and SecureToken situation when troubleshooting:
https://github.com/TravellingTechGuy/reportFileVault
Jamf Technical Paper on Administering FileVault:
https://docs.jamf.com/technical-papers/jamf-pro/administering-filevault-macos
Jamf Technical Paper on using Institutional Recovery Keys:
https://www.jamf.com/jamf-nation/articles/326/creating-and-exporting-an-institutional-recovery-key
Enabling FileVault with Jamf Connect Login on macOS 10.15 or Later:
Hello,
Thank you for your presentation during JNUC 2020. I took considerable notes to better understand how this whole process works. I learned a lot. How long would this site jeavailable in the future in case I need to refer back to it?
Thanks Chris. At this moment I have no plans of putting the site down. It’s here to stay.
Thank you very very much for your deep analysis and research!
My experience is that the recovery key will only be collected when using the EnableFDE setting in combination with the LAPSUser Settings. Therefore the user created by jamf connect login has to be a standard user. If the user is an administrator, filevault will not be activated by jamf connect login.
Please add this to the Jamf Connect documentation, it cost me days to figure this out 🙂
Cheers,
Rémi
Hi remi, that workflow works, however if you just put a profile in place with the escrow feature enabled it works fine too. And that is the preferred way imo. But LAPS with JC is indeed only for standard accounts (and that is mentioned on the Jamf Connect LAPS article).
Thank you for your reply.
When i use the escrow feature of the config profile only with EnableFDE true, CreateAdminUser true, Filevault wont be enabled by jamf connect login. It only works with CreateAdminUser false (and LAPSuser) At the moment i dont see any option to activate filevault via jamf connect EnableFDE and to get the recovery key with the setting CreateAdminUser true. I testet on 10.23.0. & 10.24.1.
As soon as i will get an answer from jamf I ll let you and your blog readers know 😉
Hi Remi. Well, I tested again because even after everything I’ve done with FV already, it always makes me doubt.
So I took my morning coffee with Jamf Pro and my test Mac on the side.
This was my setup:
– escrow profile
– jamf connect login profile with “createadminuser” and “enableFDE”
– no laps
– the additional profile to allow enableFDE at the logingwindow (even if not using laps this is needed, see https://www.jamf.com/jamf-nation/articles/708/enabling-filevault-with-jamf-connect-login-on-macos-10-15-or-later)
– login with an azure account which does not have the jamf connect admin role
=> user is admin ✅
=> FileVault Enabled ✅
=> wait for a recon (or force one)
=> recoverykey nicely escrowed in Jamf Pro ✅
So it all works fine!
The version of Jamf Pro is irrelevant and I tested with JC 2.0. However this works fine in JC 1.x too.
Don’t hesitate to open a support ticket and my colleague and I will be happy to review your setup.
Hi, i also tested again.
I can confirm, in JCL 2.0.0 & 2.0.1 it works as you describe, even without the LAPSUser setting.
With JCL 1.11.x it does not work for me on both environments. Anyway, one reason to uprade 🙂 I am happy!
Please continue your valuable work, i appreciate it!
Awesome! Thanks for the feedback!