Using Secure Enclave with Hexnode for BYOD securitySolved

Participant
Discussion
1 day ago Sep 10, 2026

We’re planning a BYOD rollout and want to understand how Secure Enclave or similar hardware-backed security fits into an existing Hexnode setup. Is Secure Enclave something Hexnode provides as a separate service, or is it enabled through policies? I’m trying to figure out what needs to be configured so corporate data and credentials can benefit from hardware-backed protection without affecting personal data on employee-owned devices.

Replies (1)

Marked SolutionPending Review
Hexnode Expert
23 hours ago Sep 10, 2026
Marked SolutionPending Review

Secure Enclave is not a separate service that needs to be installed or added to Hexnode. It is a hardware security subsystem built into supported Apple devices. Other platforms have similar hardware-backed security components, such as Android StrongBox/TEE or TPM-backed protection on Windows devices.

Hexnode leverages these native platform capabilities by enforcing OS-level policies and management configurations. For a BYOD environment, the main approach would be:

– Use iOS User Enrollment or Android Enterprise Profile Owner mode to separate corporate data from personal data.

– Enforce passcode requirements so the device can protect encryption keys using hardware-backed security.

– Configure FileVault on macOS or BitLocker on Windows where full-disk encryption is required.

– Use compliance checks to identify rooted, jailbroken, or non-compliant devices.

– Apply conditional access controls so only compliant devices can access corporate resources.

– Use remote lock or wipe actions when needed. On supported platforms, wiping managed data or the device removes the associated cryptographic keys.

For authentication workflows, Hexnode Access can be used for SSO-based login on macOS and Windows. This can help align device login with your identity provider and passwordless authentication strategy where supported.

Regards,
Mary Romero

Save