Policy still applied after removing device from device groupSolved

Participant
Discussion
4 days ago Jun 08, 2026

I removed a device from a device group that was targeted by a policy, but the policy is still showing under the device’s Policies tab. The device is no longer part of that group, the device group sync time is updated, and I also ran a device scan. Usually, I see a policy removal entry in the device action history, but this time nothing shows up. What else can keep the policy applied?

Replies (3)

Marked SolutionPending Review
Hexnode Expert
4 days ago Jun 08, 2026
Marked SolutionPending Review

Hi @it_christo !

A policy can remain applied if the device is still receiving it through another assignment path.

In Hexnode, removing a device from a targeted device group only removes that specific association. The same policy may still apply through any of the following targets:

  • Device group
  • Individual device
  • User group
  • Individual user

Open the policy and check the complete target list, especially the User Groups tab. If the policy is also assigned to a user group, any device associated with a user in that group can continue to receive the policy even after the device is removed from the device group.

To remove the policy from the device, either:

  1. Remove the user from the targeted user group, or
  2. Remove the policy assignment from that user group.

After changing the assignment, sync the device or wait for the next device check-in, then verify the device’s Policies tab again.

Best Regards,
Isabel Lora
Hexnode UEM

Marked SolutionPending Review
Participant
4 days ago Jun 08, 2026
Marked SolutionPending Review

That was the issue in my case. I was only checking the device group target and the device was definitely removed from it. The policy still had a user group listed under its targets, so the device kept getting the policy through the assigned user.

Marked SolutionPending Review
Participant
3 days ago Jun 09, 2026
Marked SolutionPending Review

Yep, this can be easy to miss. If a policy is targeted to both a device group and a user group, removing the device from only the device group will not fully disassociate the policy. The policy has to be removed from every applicable target path. Once the policy was removed from the user group, the device stopped showing that policy after sync.

Save