Manually adding FileVault Recovery Key as an Administrator

%3CLINGO-SUB%20id%3D%22lingo-sub-2940546%22%20slang%3D%22en-US%22%3EManually%20adding%20FileVault%20Recovery%20Key%20as%20an%20Administrator%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2940546%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20not%20sure%20I%20have%20the%20right%20forum%20for%20this%20question%2C%20please%20redirect%20me%20if%20necessary.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20new%20to%20using%20Microsoft%20Endpoint%20Manager%20and%20am%20assuming%20responsibility%20for%20an%20environment%20that%20was%20not%20completely%20set%20up.%20I%20have%20two%20Macs%20joined%20to%20InTune%20where%20they%20had%20previously%20initiated%20FileVault%20encryption%20prior%20to%20being%20managed.%20The%20FileVault%20recovery%20key%20was%20not%20captured%20for%20display%20on%20the%20admin%20center%20page%2C%20so%20I%20found%20guidance%20to%20run%3A%20sudo%20fdesetup%20changerecovery%20-personal%20thinking%20that%20while%20the%20device%20is%20now%20actively%20managed%20that%20it%20would%20capture%20the%20key%2C%20but%20it%20did%20not.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20see%20a%20manual%20way%20to%20upload%20the%20keys%20but%20want%20to%20be%20able%20to%20do%20that%20on%20the%20Company%20Portal%20as%20an%20admin%20rather%20than%20having%20the%20users%20do%20that.%20When%20I%20log%20in%20to%20the%20Company%20Portal%20with%20a%20Global%20Administrator%20account%2C%20I%20only%20see%20the%20devices%20that%20InTune%20has%20marked%20as%20assigned%20to%20me.%20Is%20there%20an%20Administrator%20View%20that%20I%20can%20use%20to%20access%20and%20administer%20devices%20not%20assigned%20to%20my%20account%20so%20I%20can%20manually%20upload%20the%20Recovery%20Key%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2940546%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Ecompany%20portal%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
New Contributor

I'm not sure I have the right forum for this question, please redirect me if necessary.

 

I'm new to using Microsoft Endpoint Manager and am assuming responsibility for an environment that was not completely set up. I have two Macs joined to InTune where they had previously initiated FileVault encryption prior to being managed. The FileVault recovery key was not captured for display on the admin center page, so I found guidance to run: sudo fdesetup changerecovery -personal thinking that while the device is now actively managed that it would capture the key, but it did not.

 

I see a manual way to upload the keys but want to be able to do that on the Company Portal as an admin rather than having the users do that. When I log in to the Company Portal with a Global Administrator account, I only see the devices that InTune has marked as assigned to me. Is there an Administrator View that I can use to access and administer devices not assigned to my account so I can manually upload the Recovery Key?

0 Replies