Do failed macOS Recovery Lock PIN attempts appear in Hexnode Action History?Solved

Participant
Discussion
1 month ago Jul 20, 2026

We’re setting up Recovery Lock on Apple silicon Macs using Hexnode. If a user boots into macOS Recovery and enters the wrong Recovery Lock PIN, should that failed attempt show up in Hexnode Action History? I checked Action History but couldn’t find anything for incorrect PIN attempts. We’re mainly trying to understand if there’s a way to monitor possible tampering attempts or know if the Recovery Lock password was changed or removed locally.

Replies (1)

Marked SolutionPending Review
Hexnode Expert
1 month ago Jul 23, 2026
Marked SolutionPending Review

Failed Recovery Lock PIN attempts entered directly in the macOS Recovery environment do not appear in Hexnode Action History.

Recovery Lock is enforced at the Apple hardware/boot level. Incorrect PIN entries happen locally on the Mac before the device communicates with the MDM server, so Hexnode does not receive those failed attempt events and cannot log them in Action History.

Action History can show MDM-side actions such as issuing the command to set or update the Recovery Lock password, along with the command status. It will not show each local failed PIN entry from the Recovery environment.

For monitoring, the currently reusable checks are:

1. Deploy or rotate the Recovery Lock password from Hexnode for supported Apple silicon Macs.

2. Verify the Recovery Lock status from the device’s security details in the Hexnode console.

3. Use Action History to audit MDM commands sent from Hexnode, such as setting the Recovery Lock password.

A Recovery Lock-specific compliance rule to automatically flag devices where the Recovery Lock password is changed or removed locally is not currently available. FileVault or encryption compliance is separate and only reflects disk encryption status, not Recovery Lock PIN failures.

Regards,
Mary Romero

Save