Failed Recovery Lock PIN attempts entered directly in the macOS Recovery environment do not appear in Hexnode Action History.
Recovery Lock is enforced at the Apple hardware/boot level. Incorrect PIN entries happen locally on the Mac before the device communicates with the MDM server, so Hexnode does not receive those failed attempt events and cannot log them in Action History.
Action History can show MDM-side actions such as issuing the command to set or update the Recovery Lock password, along with the command status. It will not show each local failed PIN entry from the Recovery environment.
For monitoring, the currently reusable checks are:
1. Deploy or rotate the Recovery Lock password from Hexnode for supported Apple silicon Macs.
2. Verify the Recovery Lock status from the device’s security details in the Hexnode console.
3. Use Action History to audit MDM commands sent from Hexnode, such as setting the Recovery Lock password.
A Recovery Lock-specific compliance rule to automatically flag devices where the Recovery Lock password is changed or removed locally is not currently available. FileVault or encryption compliance is separate and only reflects disk encryption status, not Recovery Lock PIN failures.
Regards,
Mary Romero