macOS passcode policy also prompts managed admin account to change passwordSolved

Participant
Discussion
3 weeks ago Aug 28, 2026

We create a managed admin account during Mac enrollment. I tested a macOS passcode policy to make users change their passwords and eventually want to enable password history.

The standard user account can change its password fine, but the managed admin account is also prompted to change its password. Is there a way to exclude the managed admin account from the passcode or password history policy?

Also, the Unlock User Account option under Device > Local Accounts is greyed out even though my technician account has admin permissions.

Replies (5)

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Aug 28, 2026
Marked SolutionPending Review

Hi @finn,

macOS passcode policies deployed through MDM are applied at the device level. Apple enforces these passcode payloads system-wide across all local accounts on the Mac.

Because of this, Hexnode cannot exclude a specific local account from the policy. If password history is enabled, that restriction applies to all local accounts, including a managed admin account created during enrollment.

If password history is not configured, the same password can usually be re-entered when prompted. However, once password history is enforced, the managed admin account is also subject to that rule.

For the greyed-out Unlock User Account option, technician admin permissions alone do not make the feature available. Advanced local account management actions, including unlocking a local user account, are available only in the Ultra plan.

Regards,
Sienna Carter
Hexnode UEM

Marked SolutionPending Review
Participant
3 weeks ago Aug 28, 2026
Marked SolutionPending Review

That makes sense, but reusing the same password won’t work for us because we need password history for standard users. We also need a reliable local admin account for troubleshooting Macs. Would LAPS solve this, or would the admin account still be affected in the same way?

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Aug 28, 2026
Marked SolutionPending Review

Hi @finn,

LAPS is the recommended approach for this use case.

You can run a LAPS policy alongside a macOS passcode policy. The passcode policy continues to enforce password requirements such as password history for local users, while LAPS independently rotates the managed local admin password.

There are two options:

1. Basic LAPS creates a new managed admin account and rotates its password.
2. Advanced LAPS can be used if you want to manage and rotate the password of an existing local admin account.

LAPS does not create a per-user exclusion in Apple’s passcode payload. The passcode policy is still system-wide. However, it removes the need to maintain a static local admin password manually, because the admin password is handled through LAPS rotation instead.

Regards,
Sienna Carter
Hexnode UEM

Marked SolutionPending Review
Participant
3 weeks ago Aug 28, 2026
Marked SolutionPending Review

We were trying to keep the existing managed admin account rather than creating a new one, so Advanced LAPS sounds like the right fit. So it’s okay to have both policies active at the same time? One for user password history and one for local admin password rotation?

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Aug 28, 2026
Marked SolutionPending Review

Hi @finn,

A macOS passcode policy and a LAPS policy can be assigned at the same time.

In that setup, the passcode policy enforces the password rules on the Mac, and the LAPS policy manages rotation for the local admin account. For an existing admin account, use Advanced LAPS. For a new managed admin account created by Hexnode, Basic LAPS can be used.

Regards,
Sienna Carter
Hexnode UEM

Save