Fix FileVault Password Sync with Active Directory ================================================== MacOS bound to Active Directory would lose sync between a user's Active Directory and FileVault passwords. This results in a FileVault unlock prompt (after boot) requiring a user's older password, and them having to enter their new password at a second login prompt. These are steps to resynchronize that password. Prerequisites: The user must be an administrator before starting this procedure. The device must be connected to the network - wired or wireless. 1. Unlock FileVault with the user's old password. Use the local administrator account if the user forgot their old password. 2. A second login screen is shown as the password entered is not valid in Active Directory. Login with the user's current AD password. 3. Start the MacOS Terminal app 4. Delete this user from FileVault. Enter the current Active Directory password when prompted by `sudo`. `sudo fdesetup remove -user username` 5. Add this user back into FileVault. Enter the current AD password when prompted by `fdesetup`. `sudo fdesetup add -usertoadd username` 6. Reboot device. User can now unlock FileVault with their current Active Directory password, and only one prompt is shown. ## FileVault Error when Adding Users Attempting to add the user back into FileVault results in `Unable to add one or more users to FileVault. (-69594)` error. Some suggested steps to troubleshoot: 1. Check if the user has a secure token with `sudo sysadminctl -secureTokenStatus username` 2. Confirm MacOS device is on the network and AD domain controllers are reachable 3. Follow the steps in this [Apple forum post](https://discussions.apple.com/thread/8088182?answerId=32389098022#32389098022). *These are untested and unknown to work.* ## NoMAD Workaround [NoMAD (No More Active Directory)](https://nomad.menu) is an open source application that keeps Active Directory and local MacOS (including FileVault) passwords in sync. It supports both types of MacOS devices -- bound and unbound to Active Directory. However, this requires user retraining as password changes follow a different workflow. On Macs bound to AD, the user should ignore prompts to change their password through MacOS. Here is a [password change example from Syracuse University](https://answers.syr.edu/display/ischool/NoMAD+Sync).