Change Password greyed out for macOS local user in HexnodeSolved

Participant
Discussion
3 weeks ago Aug 31, 2026

The Change Password option is greyed out for a local user on a managed macOS device. The tenant is on the Ultimate plan, so I’m trying to understand if this is expected or if there’s another way to reset the password without wiping the Mac.

I found a script option, but the sample macOS password change script needs the current password and we do not have it. FileVault is enabled on the Mac, and the Personal Recovery Key is escrowed in Hexnode. Is there a safe workaround for resetting the local account password?

Replies (3)

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Aug 31, 2026
Marked SolutionPending Review

Hello @vance_j ,

The Change Password remote action for local users is available only with the Ultra plan. If the portal is on the Ultimate plan, the option appears greyed out.

For macOS, there are two common alternatives:

  1. Use a shell script to change the local user password, if the current password is known.
  2. Use the escrowed FileVault Personal Recovery Key to reset the password directly on the Mac, if FileVault is enabled and the key is available in Hexnode UEM.

Since the current password is not known but the FileVault recovery key is escrowed, the FileVault recovery method is the better option and avoids a remote wipe.

Regards,
Simon Scott
Hexnode UEM

Marked SolutionPending Review
Participant
3 weeks ago Aug 31, 2026
Marked SolutionPending Review

Ok got it. The script path does not really help in this case because it asks for the current password. How do I use the escrowed FileVault key for the reset?

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Aug 31, 2026
Marked SolutionPending Review

To reset the macOS login password using the escrowed FileVault Personal Recovery Key:

  1. In Hexnode UEM, go to Manage > Devices.
  2. Open the target macOS device.
  3. Navigate to Device Info > Security Info to view the FileVault Recovery Key.
  4. On the Mac login screen, enter an incorrect password three times or more until recovery options appear.
  5. Choose the option to reset using the Recovery Key, or select Restart and show password reset options if prompted.
  6. Enter the FileVault Personal Recovery Key from Hexnode UEM.
  7. Follow the on-screen prompts to create a new password and log in.

This resets access to the local account using FileVault recovery, so the device does not need to be remote wiped.

Save