macOS ADE admin password incorrect without Hexnode LAPSSolved

Participant
Discussion
3 weeks ago Sep 04, 2026

We enroll Macs through Apple Business Manager using ADE and have Hexnode create both a standard user and a managed local admin account during setup.

The ADE profile has an admin password configured, but when I tried to use that password on one Mac, macOS reported that the admin password was incorrect. We are not currently using LAPS, and the managed admin password should not have been changed or rotated manually.

Does the ADE password remain the actual local admin password after enrollment? If not, how can we know what the current managed admin password is without changing it? Also, what is required to enable Hexnode LAPS for macOS?

Replies (3)

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Sep 04, 2026
Marked SolutionPending Review

Hi @schyler-scott,

The password configured in the ADE profile is used as an initial setup payload during macOS provisioning. It is not a live or synchronized password record after the device is enrolled.

This means the password shown in the ADE profile may not always represent the current active password of the local administrator account on the Mac. If the password was changed locally, reset through an MDM action, modified by a script, or managed by another password workflow, the ADE profile will not update to reflect that change.

If Hexnode LAPS is already enabled, the current managed password can be viewed from the device details page:

  1. Go to Manage > Devices.
  2. Select the macOS device.
  3. Open the Local Accounts or LAPS section.
  4. Locate the managed administrator account.
  5. Use the reveal option to view the current password.

If LAPS is not enabled, Hexnode cannot reveal the existing active password. In that case, the reusable options are:

– Reset the password from Manage > Devices > Local Accounts > Actions > Change Password.
– Reset it using a custom script, if that is part of your admin workflow.
– Enable Hexnode LAPS going forward so the managed admin password can be stored, viewed, and rotated securely.

Regards,
Sienna Carter
Hexnode UEM

Marked SolutionPending Review
Participant
3 weeks ago Sep 04, 2026
Marked SolutionPending Review

So if LAPS was never enabled, does that mean the managed admin password does not actually exist on the Mac?

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Sep 04, 2026
Marked SolutionPending Review

Hi @schyler-scott,

The managed administrator account and its password do exist on the Mac. macOS requires every local account to have an active password when the account is created.

The limitation is around visibility. Without LAPS, the existing password cannot be retrieved or displayed from Hexnode. You can confirm that the account exists and check its role by syncing local accounts, but the current password itself will not be available unless it is being managed through LAPS.

To inspect the account list, use Sync Local Accounts from the device actions and then review the Local Accounts tab. This helps verify whether the account is present and whether it is an administrator account, but it will not reveal the password unless LAPS is configured.

Regards,
Sienna Carter
Hexnode UEM

Save