Apple automated device enrollment not prompting for entra IDSolved

Participant
Discussion
1 month ago May 08, 2026

We’re moving to Hexnode from another MDM where new apple devices would automatically prompt the user to sign in during the Setup Assistant, which would then associate the device with that user’s Entra id account. 

In Hexnode, our users have been able to complete the setup without signing in at all, meaning IT has to assign the device owner manually afterward. I found and enabled the “Enforce Authentication” setting, but on my test device, I was still able to finish the setup without getting the Entra id login prompt. 

Also, when trying to wipe this same test device from the hexnode portal to start over, the wipe action just stays pending, even though the device is active and recently checked in. Is there something else required for Ade authentication and wipe actions to function properly? 

Replies (3)

Marked SolutionPending Review
Hexnode Expert
1 month ago May 08, 2026
Marked SolutionPending Review

Hi @diane_,
Let’s tackle both of these issues, as they usually come down to a couple of specific settings in your enrollment and remote action workflows.

  1. The Missing Entra ID Prompt
    For the authentication prompt to appear, the setting must be explicitly applied to the device via its Automated Device Enrollment (ADE) profile. Here is what you should verify:

    • Check Apple Business to ensure the device is assigned to the correct Hexnode MDM server.
    • In Hexnode, go to Admin > Apple Business/School Manager > ADE > Enrollment profile.
    • Ensure Enforce Authentication is enabled in the profile that is assigned to that specific device.
    • If you just updated this setting, the device needs to be factory reset so it can run through the Setup Assistant again and fetch the newly updated profile from Apple.
      Note: This setting only applies to devices going through enrollment. For devices that were already enrolled without authentication, you will still need to use the Change Owner action.
  2. The Stuck Wipe Command 

    This usually happens if the Wipe action was sent with the Clear Activation Lock option checked. If the device does not currently have Activation Lock enabled, checking that box unnecessarily can cause the action to fail or sit in a pending state depending on Apple’s activation lock behavior. You should use the standard Wipe action without that option selected.

Please let me know if adjusting those two settings gets your test device behaving as expected!

Best regards,
Eden Pierce
Hexnode UEM

Marked SolutionPending Review
Participant
1 month ago May 09, 2026
Marked SolutionPending Review

You were right on both counts! 

For the auth issue, I had enabled the setting in Hexnode but hadn’t actually applied the updated ADE profile to the test device. Once the correct profile was applied and the device was erased, the Entra id prompt appeared during setup, and it enrolled under the right user. 

For the wipe issue, I was indeed checking the “Clear Activation lock” box just to be safe. Sending a standard wipe command fixed the problem instantly. Thanks for the help! 

Marked SolutionPending Review
Hexnode Expert
1 month ago May 09, 2026
Marked SolutionPending Review

Hi @diane_. I am so glad to hear that both the enrollment flow and the wipe command are working perfectly for you now!

It is very common to check that Activation Lock box “just in case,” so you are definitely not the first admin to run into that stuck pending state.

Please feel free to reach out if you have any more questions as you continue migrating your fleet.

Best regards,
Eden Pierce
Hexnode UEM

Save