1.- How do i create a Dynamic group that displays all newly enrolled macs as of today. ( not a report, since i cant use that for a policy)
The idea is, to deploy a feature to newly enrolled devices 1 time via policy. Since i cant modify th epolicy to say run 1 time only. Since the policy will run 1 time, the device should clear the next day out of that group.
2.- A dynamic group that shows all my users with a bad Filevault recovery key. The Current 3 (N/a, Enabled,disabled) options do not show the faulty ones. As you can see its set by the MDM but the MDM says its broken. 
