Google authentication during Automated Device Enrollment and Google-based macOS login are two different functions.
If Google is configured as the user authentication method in the Hexnode enrollment profile, the Google credentials are used only to authenticate the user during enrollment. This does not automatically create a macOS user account that can sign in with Google credentials at the Mac login window.
To allow users to sign in to the Mac login screen using cloud identity provider credentials, you must configure and deploy Hexnode Access for macOS. Hexnode Access is the feature that connects the macOS login window with an IdP such as Google Workspace.
For the current setup without Hexnode Access:
- The Mac should create the managed local administrator account configured in the enrollment profile.
- The username shown at login, such as “Administrator”, should match the managed admin account name configured in the enrollment profile.
- The password should be the exact password configured for that managed admin account in the enrollment profile.
If the local admin password is not accepted and no other user accounts are available, the cleanest recovery path is to erase the Mac from macOS Recovery and re-enroll it using a corrected enrollment profile.
Before re-enrolling, verify the following in Hexnode:
- The Mac is assigned to the correct MDM server in Apple Business Manager.
- The device is synced into Hexnode under Automated Device Enrollment.
- The correct enrollment profile is associated with the Mac.
- The enrollment profile has a valid managed admin account configured.
- Any required macOS policies are associated with the enrollment profile before the device goes through Setup Assistant.
After erasing the Mac, connect it to Wi-Fi or Ethernet during Setup Assistant. The Remote Management screen should appear, and the Mac should enroll again with the updated profile.