Windows device locked out: can Hexnode create a local user or block USB reinstall?Solved

Participant
Discussion
9 hours ago Sep 07, 2026

We have a few Windows devices enrolled in Hexnode, but no one can sign in because the available user passwords are unknown. We tried booting from a Windows USB installer to wipe/reinstall the OS, but the keyboard and mouse stop responding at the Windows setup screen. Can Hexnode create a new local admin account if the device is sitting at the Windows sign-in screen? Also, can Hexnode prevent someone from force-reinstalling Windows using USB boot on a managed device?

Replies (3)

Marked SolutionPending Review
Hexnode Expert
5 hours ago Sep 07, 2026
Marked SolutionPending Review

A Windows device can receive Hexnode commands from the sign-in screen if it is powered on, connected to the internet, and actively checking in with Hexnode. A user does not need to be signed in for every command to execute.

If the device is online and communicating, you can create a local user from the Hexnode portal:

1. Go to Manage > Devices.

2. Select the Windows device.

3. Click Actions > Policies and Accounts > Create Local User.

4. Enter the required user details and send the command.

The device will not show a prompt for this action. If the command executes successfully, the local account is created in the background and you can use those credentials at the Windows sign-in screen.

However, if the device is offline, in sleep/hibernation, in BIOS/UEFI, in recovery, or booted from external media, it will not receive the command. In that case, the action remains pending until the device checks in again.

Regards,

Mary Romero

Marked SolutionPending Review
Participant
4 hours ago Sep 07, 2026
Marked SolutionPending Review

So just to confirm, a Windows device can still be considered online even if nobody is logged in? I always thought the MDM agent would only work after a user signs in.

Marked SolutionPending Review
Hexnode Expert
2 hours ago Sep 07, 2026
Marked SolutionPending Review

Yes. A Windows device can continue communicating with Hexnode from the sign-in screen as long as the OS is running, the Hexnode agent/service can operate, and the device has network connectivity.

The important distinction is: – Windows sign-in screen: commands may still be received if the device is online. – BIOS/UEFI, boot menu, Windows installer from USB, or recovery environment: Hexnode cannot communicate with the device because the managed Windows OS and Hexnode agent are not running. If the device’s last check-in is very old, the portal may still list the device, but newly pushed actions such as Create Local User will not execute until the device comes back online and checks in.

Save