Hi @famk_e,
For the local user deletion issue, this usually happens if the local user is configured as the default user in an Automated Device Enrollment profile. Hexnode prevents the deletion of a user currently tied to a deployment profile.
To fix this:
- Go to Admin > Apple Business Manager > Automated Device Enrollment > Enrollment Profiles.
- Among the configured enrollment profiles, see if that user has been added as the default user. If that is the case, remove or change it.
- Return to Manage > Users, select the local user, and use Actions > Edit > Delete User.
Regarding the Apple/iCloud login, Apple does not provide a direct public OIDC/OAuth login method for the macOS login window through third-party MDMs. Because of this limitation, Hexnode cannot natively force the Mac login screen to accept an Apple ID directly.
Depending on your end goal, here are the two ways to handle account management:
Scenario 1: You want users to log in to the Mac using a cloud identity
You will need to use Hexnode Access with a supported identity provider (IdP) such as Microsoft Entra ID, Okta, or Google Workspace.
- Go to Policies > macOS > Security > Hexnode Access.
- Enable Hexnode Access and select your IdP. (Note: If your organization uses Managed Apple IDs, the best practice is to federate Apple Business Manager with your IdP. Users can then use their corporate identity for their Managed Apple ID, while macOS login is handled through Hexnode Access.)
Scenario 2: You want to control iCloud usage after the user logs in
If you simply want to allow or block users from signing in to iCloud services within macOS itself, use the Restrictions payload.
- Go to Policies > macOS > Restrictions > Allow iCloud Options.
- Configure the available iCloud-related restrictions.
Best regards,
Eden Pierce
Hexnode UEM