macOS LAPS tab empty after ADE enrollmentSolved

Participant
Discussion
3 weeks ago Aug 27, 2026

I’m testing Basic LAPS on an ADE-enrolled Mac. The local admin account gets created and the LAPS action shows Success in Action History, but the device page still shows nothing under Local Accounts > LAPS, so I can’t retrieve the managed password.

I also noticed FileVault was not starting because the admin account/Secure Token state did not look right after enrollment. The LAPS policy was already associated through the ADE profile, not added manually after enrollment.

Is there anything else I should check before rolling this out to more Macs?

Replies (3)

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Aug 27, 2026
Marked SolutionPending Review

Hello @hugo_l ,

For ADE-enrolled Macs, the expected flow is:

  1. The device completes Automated Device Enrollment with the LAPS policy associated.
  2. Hexnode UEM creates the managed local admin account.
  3. The local account inventory syncs back to the portal.
  4. The managed password appears under Local Accounts > LAPS.

If the LAPS action shows Success but the LAPS tab remains empty, it usually means the local account inventory has not fully synced back yet. Run Scan device and Sync local accounts actions on the Hexnode UEM portal, then check both the Local Accounts list and the LAPS tab again.

For FileVault-related issues, also confirm that the required admin account has a Secure Token and that the Bootstrap Token is escrowed successfully. FileVault may fail to enable if the account expected to authorize it does not have the required token state.

Marked SolutionPending Review
Participant
3 weeks ago Aug 27, 2026
Marked SolutionPending Review

I ran both Scan Device and Sync Local Accounts, and both completed successfully. The LAPS tab was still empty, and the ADE-created admin account still showed Secure Token as not granted. I was hesitant to remove anything because one of the local admin accounts was the only account showing a Secure Token.

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Aug 27, 2026
Marked SolutionPending Review

Do not remove the only local admin account that has a Secure Token. Instead, try re-associating the LAPS policy with the device.

Re-associating the policy can force a fresh policy/account sync without requiring a device re-enrollment. In cases where the LAPS action succeeded but the portal did not populate the LAPS tab, this refresh can update the local account inventory correctly and make the managed password visible.

After re-association, run another device scan or local account sync if needed, then check Local Accounts > LAPS again.

Save