Secure Enclave is not a separate service that needs to be installed or added to Hexnode. It is a hardware security subsystem built into supported Apple devices. Other platforms have similar hardware-backed security components, such as Android StrongBox/TEE or TPM-backed protection on Windows devices.
Hexnode leverages these native platform capabilities by enforcing OS-level policies and management configurations. For a BYOD environment, the main approach would be:
– Use iOS User Enrollment or Android Enterprise Profile Owner mode to separate corporate data from personal data.
– Enforce passcode requirements so the device can protect encryption keys using hardware-backed security.
– Configure FileVault on macOS or BitLocker on Windows where full-disk encryption is required.
– Use compliance checks to identify rooted, jailbroken, or non-compliant devices.
– Apply conditional access controls so only compliant devices can access corporate resources.
– Use remote lock or wipe actions when needed. On supported platforms, wiping managed data or the device removes the associated cryptographic keys.
For authentication workflows, Hexnode Access can be used for SSO-based login on macOS and Windows. This can help align device login with your identity provider and passwordless authentication strategy where supported.
Regards,
Mary Romero