iPad devices not checking in to Hexnode even though the UEM app says syncedSolved

Participant
Discussion
4 days ago Sep 02, 2026

A couple of managed iPads have stopped checking in to Hexnode. The portal shows the last check-in as a long time ago, and actions like Scan Device or app updates stay pending.

The devices are online and can browse the internet. In the Hexnode UEM app, tapping Sync shows a green “Synced Successful” message, but the portal still does not update. Restarting the iPads, switching Wi-Fi, confirming automatic date/time, and checking that the MDM profile is still trusted did not fix it. The APNs certificate in Hexnode is also valid.

What else could cause iPads to look connected locally but not receive Hexnode commands?

Replies (4)

Marked SolutionPending Review
Hexnode Expert
4 days ago Sep 02, 2026
Marked SolutionPending Review

Hi @maevee,

This behavior usually points to an APNs communication issue rather than a problem with the Hexnode UEM app itself.

For iOS and iPadOS devices, Hexnode uses Apple Push Notification service to wake the device and deliver MDM commands such as Scan Device, app installation, and app update actions. If APNs traffic is blocked, the device may still have internet access and the Hexnode app may show a local sync success, but the portal will not receive the latest check-in and commands can remain pending.

Since the APNs certificate is valid and the MDM profile is still installed and trusted, check the network path next:

  1. Connect one affected iPad to an unrestricted network, such as a personal hotspot.
  2. Open the Hexnode UEM app and tap Sync.
  3. From the Hexnode portal, run Manage > select device > Actions > Scan Device.
  4. Check whether the Last Checked-in time updates.

If the device checks in over the hotspot, the primary Wi-Fi network is likely blocking Apple Push Notification service traffic, especially outbound TCP port 5223.

Regards,
Isabel Lora
Hexnode UEM

Marked SolutionPending Review
Participant
4 days ago Sep 02, 2026
Marked SolutionPending Review

I ran into something similar. The confusing part was that Safari worked fine and the Hexnode portal loaded from the iPad, so it didn’t look like a network issue at first. But commands were still stuck as pending until the device was moved off the filtered Wi-Fi.

Marked SolutionPending Review
Participant
4 days ago Sep 02, 2026
Marked SolutionPending Review

That matches what I’m seeing. The affected iPads can access the portal in the browser, and I can use the internet from them. One iPad eventually checked in after moving it to a personal hotspot, but it took a little while. Another one was still delayed at first.

Marked SolutionPending Review
Hexnode Expert
4 days ago Sep 02, 2026
Marked SolutionPending Review

Being able to open the Hexnode portal from the device confirms general internet connectivity, but it does not confirm that APNs traffic is allowed.

For iOS MDM communication, the device must be able to maintain outbound connectivity to Apple Push Notification service. If a firewall, proxy, or content filter restricts APNs traffic, Hexnode cannot reliably notify the iPad that a command is waiting. This can cause symptoms such as:

  • Last Checked-in time not updating
  • Scan Device staying pending
  • App updates not starting
  • Hexnode UEM app showing sync success locally while the portal remains unchanged
  • Multiple iPads on the same network showing the same behavior

The reusable fix is to have the network team allow outbound APNs traffic, including TCP port 5223, from the managed iPads to Apple Push Notification service. After the network rule is corrected, reconnect the devices to that Wi-Fi, open the Hexnode UEM app, tap Sync, and run Scan Device again from the portal.

Until the firewall or content filter is updated, using a personal hotspot or another unrestricted network is a valid workaround to get affected iPads checked in.

Regards,
Isabel Lora
Hexnode UEM

Save