Hey @benjay,
This behavior is caused by the Windows OOBE Work or School account flow, not by Hexnode.
During Windows 11 OOBE, the Work or School sign-in option expects a Microsoft Entra ID identity. If the account is from Google Workspace and does not have a matching Microsoft-managed identity/license, Microsoft Entra ID can reject the sign-in and return an invalid_client error.
For Google Workspace-based enrollment, avoid using the Windows OOBE Work or School cloud sign-in prompt. You can use either of these approaches:
Option 1: Manual enrollment after creating a local account
- At OOBE, disconnect the device from the internet or use a dummy blocked email/password to force Windows into local account creation.
- Complete OOBE with a local offline account.
- Reconnect the device to the internet after reaching the Windows desktop.
- Open the Hexnode enrollment URL in a browser.
- Download and run the Hexnode Agent installer.
- In the Hexnode authentication window, change the authentication domain from Local to the configured Google Workspace domain.
- Sign in with the user’s Google Workspace credentials and complete enrollment.
Option 2: Automated enrollment using a provisioning package
For a more automated deployment, use a Windows Provisioning Package (.ppkg) with Hexnode Open Enrollment. This lets you preconfigure the enrollment flow and reduce end-user action during setup.
If the goal is minimal user interaction, the provisioning package method is the recommended approach. For more details, refer to our document on “How to enroll Windows devices using provisioning package files?“.
Best Regards,
Isabel Lora
Hexnode UEM