macOS LAPS password field blank after policy assignmentSolved

Participant
Discussion
2 months ago Apr 04, 2026

Hi everyone. We are in the process of rolling out LAPS for our macOS fleet to manage local administrator accounts. I have configured the LAPS policy in Hexnode and assigned it to a test group of MacBooks. The devices are enrolled, and the console shows the policy is successfully associated.

However, when I navigate to the device details to retrieve the password, the password field is completely blank. I have verified that the target admin account exists on the Mac, but Hexnode just isn’t displaying the generated password. Has anyone else encountered this empty password field issue with macOS LAPS, and is there a step I might be missing to force it to populate?

Replies (1)

Marked SolutionPending Review
Hexnode Expert
2 months ago Apr 04, 2026
Marked SolutionPending Review

Hello,

Thanks for reaching out to Hexnode Connect.

If the LAPS password field appears blank for a macOS device despite the policy showing as associated, it typically indicates that the policy state has not fully refreshed within the console or applied on the device side.

To resolve this and force the password to populate, you can trigger a policy re-evaluation by following these steps:

  1. Open the existing LAPS policy that is assigned to your macOS devices.
  2. Save the policy again (you do not need to make any actual changes to the settings).
  3. Allow the Mac to complete its next sync with Hexnode.
  4. Refresh the device summary page in your console and check the LAPS password field again.

Resaving the policy forces Hexnode to reprocess the payload. Once the device syncs, the generated password should successfully report back to the console.

For a complete troubleshooting checklist regarding this issue, please ensure:

  • The device is correctly identified as a macOS endpoint.
  • The LAPS policy is actively assigned to the device or its respective device group.
  • The LAPS policy has been resaved to trigger a refresh.
  • The device page is refreshed only after the next successful sync.
  • The Action History tab confirms that the policy association action was completed successfully.

If the password remains blank after trying these steps, review whether the policy is actually reaching the device or if there are any network constraints preventing the device from communicating its status back to the MDM server.

I hope this helps. If you find any more issues or need further assistance feel free to reach out.

Best regards,
George,
Hexnode UEM

Save