Set up macOS Account-Driven User Enrollment in Hexnode without self-hosted service discoverySolved

Participant
Discussion
5 hours ago Oct 05, 2026
I’m trying to enable Apple Account-Driven User Enrollment for macOS through Hexnode. The users have Managed Apple IDs in Apple Business Manager, but the Macs themselves are not pre-registered in ABM.
When a user tries to enroll from System Settings, they see: “Your Apple account does not support the expected services on this device. Please contact your administrator to sign in.”
I found references to service discovery and a JSON file, but we do not currently have a web server set up to host the service discovery file. Is there a way to use Account-Driven User Enrollment for Macs without setting up self-hosted service discovery? Also, some Google IDP enrollment options are grayed out in the portal. Are those required for this enrollment flow?

Replies (1)

Marked SolutionPending Review
Hexnode Expert
24 minutes ago Oct 05, 2026
Marked SolutionPending Review

Yes. If you do not have a web server configured to host the service discovery JSON file, use the Redirect option for Account-Driven Enrollment in Hexnode.

Configure it as follows:

1. Go to Admin > Enrollment > Authentication Type.

2. Select Enforce Authentication.

3. Scroll to Enrollment Ownership.

4. Set Ownership type to Personal.

5. Set Account driven enrollment configuration to Redirect.

6. Save the configuration.

For Account-Driven User Enrollment, the ownership type must be set to Personal, even if the Mac is organization-owned. This is because Apple’s User Enrollment workflow enrolls the device under a specific managed user account.

After this is configured, the macOS enrollment flow is:

1. The user opens System Settings > General > Device Management > Work or School Account.

2. The user clicks Sign In.

3. The user enters their Managed Apple Account.

4. The Mac performs service discovery and is redirected to the Hexnode enrollment page.

5. The user reviews the enrollment page/EULA and clicks Enroll.

6. If authentication is enforced, the user authenticates.

7. macOS prompts the user to sign in to iCloud with the Managed Apple Account password.

8. The user allows Remote Management.

9. Enrollment completes, and the managed account appears under Device Management.

The Redirect URL is the enrollment URL that the Mac is directed to during this process. You generally do not need to manually give this URL to the user; it is used by the enrollment flow after the user signs in with the Managed Apple Account.

Regards,

Mary Romero

Save