Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

massoo

macrumors newbie
Original poster
Jun 5, 2023
9
0
Hello,

We are trying to make sure that every MAC that we have is encrypted, however we dont have any commercial MDM solution. We have a bunch of devices registered in Apple Business Manager (ABM).

I would like to understand is there any way either through scripting / mobileconfig / etc. to do:

1. Enforce Full Disk Encryption with File Vault for all users using PRK (Personal Recovery Keys)
2. Upload PRK's to a folder in Google Drive for safe-keeping (I already do this for my Windows Devices) or recovery codes
 
Yes.
If you use iMazing, you will notice that values that require MDM enrollment are marked with “Supervised only”. In Apple’s documentation they appear with “Requires a supervised device.”
The FileVault 2 payload doesn’t have such values.
 
Thank you for the replies, I tried to create and import but did not work ... does anyone has a working sample that can be imported through script or terminal ?
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.