iOS Find My blocked by Hexnode policy and apps reinstalling after policy editsSolved

Participant
Discussion
3 weeks ago Sep 18, 2026

Users on our managed iPhones are unable to use Apple’s Find My to locate their devices. I’m checking whether there is any Hexnode policy setting that can block Find My on iOS.

I also noticed another issue: when I modify a policy and push the update to devices, some apps appear to get deleted and reinstalled. These apps are deployed as required apps. Is there a way to stop this from happening every time a general policy change is made?

Replies (1)

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Sep 18, 2026
Marked SolutionPending Review

Hi @yu-yan,

Hexnode UEM can restrict Apple’s Find My functionality on supervised iOS devices through iOS Advanced Restrictions.

Check the policy associated with the affected devices:

  1. On your Hexnode UEM console, go to Policies.
  2. Open the iOS policy applied to the devices.
  3. Navigate to iOS > Advanced Restrictions > Allow Security and Privacy Settings.
  4. Make sure the following options are enabled:
    • Find My Device
    • Modify Find My Friends

If either of these options is disabled, users may be restricted from using Apple’s Find My services on supervised iOS devices. Enable both options and save the policy, then allow the updated policy to sync with the devices.

About the app reinstallation part, when Required Apps are bundled into a policy that is frequently modified, Hexnode may re-evaluate the application payload when the policy is updated. This is more noticeable if app removal behavior is enabled for the required apps, because the app payload can be removed and then installed again as part of policy reprocessing.

To avoid this, use separate policies:

  • Create one standalone policy only for Required Apps.
  • Create a separate policy for iOS restrictions, device functionality settings, and other general configurations.
  • Avoid frequently editing the policy that contains the Required Apps payload unless you are intentionally changing app deployment.

This way, changes to general iOS restrictions should not cause the required app deployment payload to be reprocessed unnecessarily.

Regards,
Sienna Carter
Hexnode UEM

Save