Windows enrollment: local admin rights vs Hexnode users and enrollment profilesSolved

Participant
Discussion
18 hours ago Sep 03, 2026

I’m setting up a batch of Windows laptops in Hexnode and got confused about the enrollment flow. Do I need to create a new Hexnode user for each laptop, or can I enroll all devices using one user? Also, the devices need to be enrolled from a local admin account so they stay compliant with our Windows policies. I also noticed that my plan only seems to allow a limited number of enrollment profiles. Does that mean I can only enroll a few devices, or can one enrollment profile be reused?

Replies (5)

Marked SolutionPending Review
Hexnode Expert
15 hours ago Sep 03, 2026
Marked SolutionPending Review

For Windows device enrollment, it helps to separate two concepts: Hexnode Users and Enrollment Profiles.

Hexnode Users represent who the device belongs to. If each Windows laptop is assigned to a specific employee, create separate Hexnode users and assign the devices to the correct users. If the devices are shared or centrally managed, you can use a generic user for enrollment.

Enrollment Profiles are different. An enrollment profile is the configuration template used to generate the enrollment link and define enrollment-related settings. You do not need a separate enrollment profile for every user or device. A single active enrollment profile can be used to enroll multiple Windows devices.

For local administrator enrollment:

  1. Sign in to the Windows device using a local administrator account.
  2. Open the enrollment URL generated from the active enrollment profile.
  3. Download and run the Hexnode installer.
  4. Complete the enrollment from that administrator session.

Running the installer from a local admin account gives Hexnode the required system-level permissions to apply supported Windows policies and compliance settings, such as password rules, BitLocker-related configurations, or OS update settings, depending on your plan and policy configuration.

Marked SolutionPending Review
Participant
12 hours ago Sep 03, 2026
Marked SolutionPending Review

That clears up part of it, but I’m still confused about the “one active profile” part. If I create separate Hexnode users for employees, won’t each user need a separate enrollment profile too?

Marked SolutionPending Review
Hexnode Expert
10 hours ago Sep 03, 2026
Marked SolutionPending Review

No, each user does not need a separate enrollment profile. Think of it this way:

  • Hexnode User = the person or owner associated with the device.
  • Enrollment Profile = the enrollment settings/template used to enroll the device.

You can have many Hexnode users and still enroll their devices through the same active enrollment profile. The profile controls how enrollment works, while the user assignment controls who the device is associated with in the portal.

If your license restricts creating additional enrollment profiles, that only limits how many separate enrollment templates you can configure. It does not prevent enrolling multiple Windows devices through the active profile.

Marked SolutionPending Review
Participant
8 hours ago Sep 03, 2026
Marked SolutionPending Review

So the correct flow is: create users if I want ownership tracking, keep using the same active enrollment profile, open the enrollment URL on each Windows laptop, and run the installer while logged in as local admin. Is that right?

Marked SolutionPending Review
Hexnode Expert
18 minutes ago Sep 04, 2026
Marked SolutionPending Review

Yes, that is correct.

Use individual Hexnode users when you want each device mapped to a specific employee. Use a shared or generic user only if the devices are not assigned to specific people.

For the enrollment profile, use the single active profile to generate the enrollment URL and enroll all required Windows devices. If your plan does not allow additional enrollment profiles, make any required enrollment setting changes within the active profile instead of creating new ones.

The key Windows-specific point is to start enrollment from a local administrator account so the Hexnode installer can complete setup with the permissions needed for supported device management actions.

Save