Hexnode policy for fingerprint unlock, and failed passcode alertsSolved

Participant
Discussion
3 weeks ago Jul 22, 2026

I’m reviewing Hexnode policies for iOS, Android, macOS and Windows devices and couldn’t find clear options for a few things.

Can Hexnode enforce fingerprint unlock instead of just a passcode? Is there a way to set a delay after wrong passcode attempts, or alert admins if a user enters the wrong passcode more than 10 times?

Replies (5)

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Jul 22, 2026
Marked SolutionPending Review

Hi @_ashur,

Hexnode can enforce passcode requirements, but it cannot force users to unlock devices specifically with fingerprint or biometric authentication.

You can configure passcode policies such as complexity, length, age, and failed attempt behavior, but biometric unlock is controlled by the operating system and the end user’s device settings.

For failed passcode attempts and delays:

iOS and Android handle passcode retry delays automatically at the OS level. Hexnode cannot customize those delay timers.
– Hexnode can configure the maximum number of failed passcode attempts before a secure factory wipe is triggered, where supported.
macOS allows configuration of custom delays between failed login attempts.

For admin alerts, Hexnode does not receive real-time failed passcode attempt counts from iOS or Android, so an alert such as “notify admin after 10 wrong passcode attempts” cannot be configured directly. You can, however, use compliance rules and admin notifications when a device becomes non-compliant with configured security requirements.

Regards,
Sienna Carter
Hexnode UEM

Marked SolutionPending Review
Participant
3 weeks ago Jul 24, 2026
Marked SolutionPending Review

What about factory reset? If the device is wiped, will it automatically come back into Hexnode with the same policies?

Marked SolutionPending Review
Hexnode Expert
2 weeks ago Jul 24, 2026
Marked SolutionPending Review

Hi @mila_diaz,

Automatic re-enrollment after a factory reset depends on how the device was originally enrolled.

A device will be forced back into Hexnode during setup only if it is assigned through a hardware-level or automated deployment program, such as:

iOS or macOS: Apple Business or Apple School Manager
Android: Google Zero-Touch Enrollment or Samsung Knox Mobile Enrollment
Windows: Windows Autopilot

After the device re-enrolls, policy assignment depends on the settings under Admin > Enrollment > Re-enrollment Settings.

If the portal is configured to retain configurations or keep the existing owner, Hexnode recognizes the returning device and reapplies the previous ownership, groups, and policies. If it is configured to enroll as a new device or change owner, policies are applied based on the new user or group assignment.

Regards,
Sienna Carter
Hexnode UEM

Marked SolutionPending Review
Participant
2 weeks ago Jul 28, 2026
Marked SolutionPending Review

For non-compliance, does Hexnode take an automatic action by default? Also, is iPhone location tracking available?

Marked SolutionPending Review
Hexnode Expert
2 weeks ago Jul 28, 2026
Marked SolutionPending Review

Hi @lila_ace,

When a device violates a compliance rule, such as having a blocklisted app, or being jailbroken/rooted, Hexnode marks the device as Non-Compliant in the portal. The violation is also logged in reports, and administrator email alerts can be configured from Admin > Alert Profiles.

For iPhone location tracking, Hexnode can report location, but the following are required:

– The Hexnode UEM agent app must be installed on the iPhone.
– Location Services must be enabled on the device.
– Location permission for the Hexnode app must be set to Always Allow.

Apple’s native MDM protocol does not provide direct GPS tracking by itself, so the Hexnode app and the required location permission are necessary.

Regards,
Sienna Carter
Hexnode UEM

Save