Policy shows Direct and Device Group mapping but no trash iconSolved

Participant
Discussion
1 week ago Aug 05, 2026

One of our managed devices is showing the same policy as associated in two ways: Direct and through a device group. On other devices, I usually only see the group association.

I was trying to remove this policy from the device and assign a different one, but the trash can icon is not showing up like it normally does. The device is part of a dynamic device group, and the policy appears to be linked from that group as well.

Why does the Direct mapping show up, and how do I remove the policy from just this device without affecting the rest of the group? Also, can I add the policy back to this device later if needed?

Replies (1)

Marked SolutionPending Review
Hexnode Expert
1 week ago Aug 05, 2026
Marked SolutionPending Review

Hello @juan_garcia ,

This usually happens when the same policy reaches a device through more than one target path.

For example, the policy may be assigned:

  • Directly to the individual device
  • Through a device group that the device belongs to

When a policy is inherited from a device group, it cannot be removed directly from the device’s Policies tab. The trash can icon is available only when the policy assignment can be removed at the device level. Group-based assignments must be managed from the group or policy target configuration.

For a dynamic device group, the usual way to remove the policy from only one device is to exclude that device from the dynamic group:

  1. Go to Manage > Device Groups.
  2. Open the dynamic device group that applies the policy.
  3. Go to Criteria.
  4. Add the device to the Exceptions list.

Once excluded, the device will no longer receive policies through that dynamic group. Other devices in the group will remain unaffected.

If you want the device to receive the same group policy again later, remove the device from the group’s exception list.

Regards,
Simon Scott
Hexnode UEM

Save