Hello,
Thanks for reaching out to Hexnode Connect.
Yes, this is entirely expected behavior and not a bug.
While Hexnode allows you to configure SSO identity providers (such as Google, Microsoft, or Okta) as the primary login method for your technicians, local Hexnode account authentication is intentionally retained. Because of this, it is not exposed as a standard option that can be disabled under your Logon restrictions.
This design acts as a critical safeguard to prevent complete administrator lockout. If your external identity provider ever experiences downtime, becomes misconfigured, or runs into authentication issues, the local login remains available as a secure fallback path. This ensures that administrators can always access the console to resolve issues and maintain operations.
You can continue using Google SSO as your team’s primary login method and simply treat the local login option as a built-in recovery measure.
I hope this clarifies how technician authentication is designed! Feel free to reach out if you have any more doubts or need further assistance.
Best regards,
George,
Hexnode UEM