Hi @ezekiel,
While a custom API-based workflow can technically be built, it is not recommended for this scenario. Passing passwords via API requires securely storing, transmitting, and constantly updating sensitive credentials whenever a user changes their password.
For Google Workspace-managed users, the best practice is to use Hexnode’s native Google Workspace integration combined with OAuth. This means you do not need to send or store the password in the MDM at all.
Here is the recommended workflow:
- Integrate Google Workspace with Hexnode from your portal and allow it to sync your users.
- Create an email configuration policy in Hexnode UEM.
- Use the dynamic variable %email% in the email address field.
- Enable OAuth / Google Sign-In for authentication.
- Assign the policy to the required devices or device groups.
With this setup, Hexnode automatically pre-fills the assigned user’s Google Workspace email address on the device. The user is then redirected to the official Google authentication flow to enter their password directly. If their password ever changes in the future, no updates are required from the MDM side!
Please let me know if you need any help getting the workspace integration configured.
Best regards,
Eden Pierce
Hexnode UEM