FDE recovery key escrow status as a filter
it would be helpful to include the FDE recovery key escrow status (rather than the key itself) as well as the firmware password status.
As a company policy, we'd like to enforce these and check who forgot to turn it on or off. Going through devices one by one is quite hard.
2
votes

-
andy commented
The FDE key on the portal was not valid as it had changed so was unable to recover the mac had to DFU it.
I would like to see FDE keys being updated in the portal when they're changed / or at least checked ( sudo fdesetup validaterecovery ) with a valid/invalid flag against the device in the portal.