You can use a policy to issue a new FileVault recovery key to computers with macOS 10.14 or later that have FileVault activated. This allows you to do the following:
Replace a personal (also known as "individual") recovery key that has been reported as invalid and does not match the recovery key stored in Jamf Pro.
Update the recovery key on computers on a regular schedule, without needing to decrypt and then re-encrypt the computers.
Requirements
To issue a new personal recovery key to a computer, the computer must have:
FileVault activated
One of the following two conditions met:
An existing, valid personal recovery key stored in Jamf Pro
A FileVault enabled user account with a secure token
To issue a new institutional recovery key to a computer, the computer must have:
FileVault enabled
A FileVault enabled user account with a secure token