That would explain the behavior. Once the correct macOS policy is applied, Hexnode can enforce the FileVault configuration on the device. After applying the policy, wait for the device to sync and then verify the action history again. If the FileVault policy shows as applied, restart the Mac if the encryption status does not update immediately. The device should report as encrypted once FileVault is enabled and the updated status is synced back to Hexnode. To prevent this from happening again, it is a good idea to verify the policy targets or dynamic group conditions used for FileVault enforcement, especially for newly enrolled or recently reassigned Macs.