Deploying a Disk Encryption Configuration Using a Policy

Jamf Pro Documentation 11.16.0

Solution
Application
Content Type
Technical Documentation
Utilities & Services
version
11.16.0
ft:locale
en-US
vrm_version
11.16.0

The event that activates FileVault depends on the enabled FileVault user specified in the disk encryption configuration and whether the computer is Apple File System (APFS) enabled. If the enabled user is a management account and the computer is APFS enabled, FileVault is activated on a computer at the next login without needing to reboot. If the computer is HFS+ formatted with the "Management Account" enabled user, FileVault is activated on a computer the next time the computer restarts. If the enabled user is "Current or Next User", you can modify when FileVault is activated on a computer. Options include the following:
  • The next time the computer restarts

  • The next time the current user logs out

  • The next login or after multiple user logins (ranging from two to six logins)
    Note: If the restart is done using a built-in policy, FileVault will not be activated.
  1. In Jamf Pro, click Computers in the sidebar.
  2. Click Policies in the sidebar.
  3. Click New.
  4. In the General payload, enter a display name for the policy (e.g., "FileVault Disk Encryption").
  5. Select a trigger.
  6. Choose "Ongoing" from the Execution Frequency pop-up menu.
  7. Select the Disk Encryption payload and click Configure.
  8. Choose "Apply Disk Encryption Configuration" from the Action pop-up menu.
  9. Choose the disk encryption configuration from the Disk Encryption Configuration pop-up menu.
  10. Choose an event from the Require FileVault 2 pop-up menu to specify when users must enable disk encryption.
  11. (Optional) If Management Account is selected as the enabled FileVault user in the disk encryption configuration, do the following:
    1. Select the Restart Options payload and configure restart settings for the computer.
      Note:

      Select Restart from the appropriate pop-up menu to include a restart prompt. Select Restart immediately to restart without prompting. The Restart option does not work if configured to encrypt at logout.

    2. You can select Perform authenticated restart on computers with FileVault 2 enabled to allow computers with macOS 10.8.2 or later that are FileVault enabled to be restarted without requiring an unlock the next time the computer starts. This affects future reboots, but does not apply to the setup of the original encryption policy.
    3. Click the User Interaction tab and customize the restart message displayed to users.
  12. Click the Scope tab and configure the scope of the policy.
  13. Click Save .
The policy runs on computers in the scope the next time they check in with Jamf Pro and match the selected trigger in the General payload.