Android Enterprise enrollment profile has no WPA3 option in HexnodeSolved

Participant
Discussion
4 months ago May 09, 2026

Hi everyone. I’m setting up Android Enterprise QR code enrollment in Hexnode and noticed the Wi-Fi security options are limited to WEP, WPA/WPA2, or 802.1x EAP. Our network strictly uses WPA3, and we prefer not to downgrade our security just to onboard devices. Is there any way to use WPA3 during initial enrollment? If we set our access points to WPA2/WPA3 Mixed Mode and select WPA/WPA2 in the Hexnode profile, will that restrict the device to WPA2, or can it still negotiate WPA3? Alternatively, can we skip Wi-Fi entirely and enroll these devices over 5G/mobile data?

Replies (1)

Marked SolutionPending Review
Hexnode Expert
4 months ago May 09, 2026
Marked SolutionPending Review

Hello,
Thank you for reaching out to Hexnode Connect!
You are correct that the enrollment profile currently provides WEP, WPA/WPA2, and 802.1x EAP options. However, you can seamlessly onboard your devices without compromising security using two methods.

  1. Mixed Mode Negotiation: If you configure your access point to WPA2/WPA3 Mixed Mode (Transition Mode), you can select WPA/WPA2 in your Hexnode enrollment profile. This selection simply allows the device to accept the provisioning payload. The actual security negotiation occurs directly between the device and the access point, meaning they will securely establish a WPA3 connection if both support it.
  2. Cellular Enrollment: For strict WPA3-only networks, bypassing Wi-Fi during setup is the cleanest workaround. In your enrollment profile, set the Wi-Fi Settings to No Wi-Fi network configuration. Insert an active SIM card into the device before scanning the QR code, and it will instantly provision over mobile data. Once the device is enrolled, you can then push your strict WPA3 network configuration to it via a standard Hexnode policy.

I hope this clarifies your deployment options!
Best regards,
George
Hexnode UEM.

Save