Hi @im_dany,
Based on the behavior described, this does not appear to be a misconfigured Hexnode policy if the Secure Wi-Fi Settings option is already disabled and the same policy works on other Macs.
The likely cause is a local macOS state persistence issue where the native Wi-Fi authorization setting remains enabled on specific devices even after the MDM restriction is removed or updated. In that state, reapplying the policy may not override the stuck local toggle until it is manually disabled once.
For prevention and fleet rollout:
– Apply the intended Wi-Fi restriction policy soon after enrollment, before devices are handed over for long-term use.
– For existing Macs, test the policy in stages instead of pushing to the entire fleet at once.
– If a standard user is still prompted for admin credentials, check whether the local “Require administrator authorization to change networks” option is enabled.
– If it is stuck on, reset or recover local admin access, disable the setting locally, then remove and re-associate the Hexnode policy.
At the moment, the confirmed remediation is the manual local change followed by a clean policy sync. If the same behavior appears across many Macs, it is worth reviewing affected macOS versions and enrollment history to identify any common pattern.
Regards,
Sienna Carter
Hexnode UEM