macOS ADE enrollment stuck at Administrator login instead of Google loginSolved

Participant
Discussion
4 days ago Jul 23, 2026

I’m setting up a Mac through Apple Business Manager and Automated Device Enrollment in Hexnode. The Mac was factory reset, assigned in ABM, synced to Hexnode, and an enrollment profile was associated.

During setup, I selected Google authentication and used my Google account to complete enrollment. I expected that to let me sign in to macOS with my Google credentials afterward.

Instead, after enrollment the Mac restarted to a macOS login screen showing only “Administrator”. The password I configured for the managed admin account in the enrollment profile doesn’t seem to work, and there are no other users listed.

Is Google authentication during enrollment supposed to create a Google-based macOS login? Also, what is the right way to recover and re-enroll the Mac if it is stuck at the Administrator login screen?

Replies (5)

Marked SolutionPending Review
Hexnode Expert
3 days ago Jul 24, 2026
Marked SolutionPending Review

Google authentication during Automated Device Enrollment and Google-based macOS login are two different functions.

If Google is configured as the user authentication method in the Hexnode enrollment profile, the Google credentials are used only to authenticate the user during enrollment. This does not automatically create a macOS user account that can sign in with Google credentials at the Mac login window.

To allow users to sign in to the Mac login screen using cloud identity provider credentials, you must configure and deploy Hexnode Access for macOS. Hexnode Access is the feature that connects the macOS login window with an IdP such as Google Workspace.

For the current setup without Hexnode Access:

  1. The Mac should create the managed local administrator account configured in the enrollment profile.
  2. The username shown at login, such as “Administrator”, should match the managed admin account name configured in the enrollment profile.
  3. The password should be the exact password configured for that managed admin account in the enrollment profile.

If the local admin password is not accepted and no other user accounts are available, the cleanest recovery path is to erase the Mac from macOS Recovery and re-enroll it using a corrected enrollment profile.

Before re-enrolling, verify the following in Hexnode:

  • The Mac is assigned to the correct MDM server in Apple Business Manager.
  • The device is synced into Hexnode under Automated Device Enrollment.
  • The correct enrollment profile is associated with the Mac.
  • The enrollment profile has a valid managed admin account configured.
  • Any required macOS policies are associated with the enrollment profile before the device goes through Setup Assistant.

After erasing the Mac, connect it to Wi-Fi or Ethernet during Setup Assistant. The Remote Management screen should appear, and the Mac should enroll again with the updated profile.

Marked SolutionPending Review
Participant
3 days ago Jul 24, 2026
Marked SolutionPending Review

That explains a lot. I had set up the Google integration and thought that meant the Mac would let me sign in with Google after enrollment. In my portal, the Hexnode Access option is greyed out. Does that mean Google login at the macOS login screen is not available to me?

Marked SolutionPending Review
Hexnode Expert
3 days ago Jul 24, 2026
Marked SolutionPending Review

Yes. If Hexnode Access is greyed out, it means the feature is not available in the current plan or configuration.

Without Hexnode Access, Google authentication can still be used for enrollment authentication, but not for logging in to the Mac itself. In that case, macOS login must be handled through local accounts, such as the managed administrator account created from the enrollment profile.

So the expected behavior is:

  • Google credentials during enrollment: validates the enrolling user.
  • Hexnode Access policy: enables cloud IdP login at the macOS login window.
  • Managed admin in enrollment profile: creates a local admin account on the Mac after enrollment.

If the Mac is stuck with only the Administrator account and the configured password does not work, erase and re-enroll the Mac with an updated enrollment profile. Once re-enrolled, confirm that the device appears in Hexnode and check that the local account is visible under the device’s Local Accounts section.

Marked SolutionPending Review
Participant
3 days ago Jul 24, 2026
Marked SolutionPending Review

I ended up putting the Mac into recovery, erasing it, and enrolling it again after updating the enrollment profile and associated policies. This time it came up with the new profile and showed in Hexnode properly. The important piece I missed was that Google enrollment authentication is not the same thing as Google login for macOS. For now I’m keeping the local admin account in the enrollment profile.

Marked SolutionPending Review
Hexnode Expert
3 days ago Jul 24, 2026
Marked SolutionPending Review

Keeping a local administrator account in the enrollment profile is recommended, even if cloud login is used later. It provides a fallback admin account for troubleshooting device access, policy deployment, and recovery scenarios. For future enrollments, the suggested flow is:

  1. Assign the Mac to the Hexnode MDM server in Apple Business Manager.
  2. Sync Automated Device Enrollment devices in Hexnode.
  3. Associate the correct enrollment profile with the Mac.
  4. Configure a managed local admin account in the enrollment profile.
  5. Associate required macOS policies with the enrollment profile.
  6. Erase or start the Mac from Setup Assistant.
  7. Connect to a network during setup.
  8. Complete the Remote Management screen.
  9. Confirm that the Mac appears under Manage > Devices in Hexnode.

If apps are needed immediately after enrollment, add them to the enrollment profile. If the apps must remain installed and be reinstalled if removed, deploy them through a Required Apps policy.

Save