iOS devices still require encrypted iTunes/Finder backups when Hexnode restriction is disabledSolved

Participant
Discussion
2 months ago Jul 26, 2026

Hi everyone. I’m seeing some weird behavior on our supervised, corporate-owned iOS devices. Whenever I connect them to a computer and try to run a local backup using iTunes (Windows) or Finder (macOS), I am immediately forced to enter an “Encrypt local backup” password.

I checked my Hexnode portal, and the “Force encrypted backup” restriction is completely disabled across all active policies. There are no Exchange ActiveSync payloads, no Screen Time restrictions, and the devices were fully factory reset after being migrated from our old MDM via Apple Business Manager. Why is iTunes/Finder still forcing encrypted local backups if Hexnode isn’t enforcing it?

Replies (1)

Marked SolutionPending Review
Hexnode Expert
2 months ago Jul 26, 2026
Marked SolutionPending Review

Hello,

Thank you for reaching out to Hexnode Connect!

This is a very common point of confusion. What you are experiencing is not a misconfiguration in your Hexnode portal, but rather a native Apple security protocol overriding your MDM settings.

When you enroll a device into an MDM, iOS receives configuration profiles that are often encrypted to protect corporate identity certificates, communication tokens, and other sensitive management data. Apple enforces a strict, OS-level security rule: if an encrypted configuration profile is present on an iOS device, any local backups made via iTunes or Finder must also be encrypted.

This native safeguard ensures that managed corporate data cannot be dumped into an unencrypted, plaintext backup file on a local computer.

So, while the “Force encrypted backup” toggle being disabled in Hexnode means the MDM isn’t actively sending a restriction command, iOS itself is stepping in and forcing the encryption requirement due to the nature of the profiles currently installed on the device.

I hope this clarifies the behavior you are seeing! Please feel free to reach out if you have any further questions.

Best regards,
George
Hexnode UEM.

Save