FileVault recovery is not possible when MNE
password expiry policy is enabled on
macOS High Sierra, or later systems.
After a user completed a FileVault recovery, but was then prompted to reset their password, the Change Password window suppressed the Reset Password window. The suppression of the Reset Password window can occur within a fraction of a second. The Password Expire policy controls the Change Password window, and this window is asking the user for their old password. This sequence leads to the following:
- Recovery to desktop is not possible because the user does not remember the old password.
- FileVault Recovery to the desktop is not possible. The user is asked for their old password at the operating system logon prompt.