Category filter
How to retain policies when removing a device from a Device Group in Hexnode UEM?
TL;DR
Removing a device from a device group removes the policy associations applied through that group. To keep the same policy configurations on the device, directly associate the required policies with the individual device before removing it from the device group. If a policy is targeted to both the device group and the individual device, the policy remains applied through the direct device association after the device is removed from the group.
Executive Summary
Device groups in Hexnode are commonly used to apply policies to multiple devices at once. When a device is removed from a device group, the policies associated through that device group are no longer applied to the device. To prevent policy configurations or managed content from being removed, associate the required policies directly with the individual device before removing it from the group.
This approach is useful when a device must be moved out of a group while retaining selected policies. Policies can be targeted at multiple entities, including both device groups and individual devices. A direct device-level policy association continues to apply even after the group-level association no longer applies.
When to use this workflow
- A device must be removed from a device group, but its existing policy configurations should remain unchanged.
- The same policy is already associated with both the device group and the individual device.
- A policy needs to remain on a specific device after the group-level policy association is removed.
Important behavior to know before removing a device from a device group
When a device is removed from a device group, the policy associations inherited from that group are removed from the device. However, policies that are directly associated with the device remain applied.
Example: If a policy is associated with both a device group and an individual device, removing the device from the device group removes only the group-based association. The direct device association remains, so the policy continues to apply to the device.
Note: If a policy is applied only through the device group and is not directly associated with the device, that policy will no longer apply to the device after it is removed from the group.
Preserve policies before removing a device from a device group
- Identify the policies currently applied to the device through the device group.
- Go to the Policies tab in the Hexnode UEM portal.
- Select one of the policies that must remain on the device.
- Click Manage > Associate Targets. Alternatively, open the policy, click Modify, and go to Policy Targets.
- Click Devices or +Add Devices.
- Select the specific device that must retain the policy.
- Click OK or Associate.
- Save the policy.
- Repeat the same process for each policy that must remain on the device.
- After the required policies are directly associated with the device, remove the device from the device group.
Warning: Test this workflow with a test device before applying it to production devices. This helps verify that the expected policies remain on the device after it is removed from the device group.
Expected result
After the device is removed from the device group, policies that were directly associated with the device remain applied. Policies that were associated only through the device group are removed from the device.
Frequently Asked Questions
Can a device keep a policy after it is removed from a device group?
Yes. The policy must be directly associated with the individual device before the device is removed from the device group. Direct device-level policy associations remain applied after group membership changes.
What happens if a policy is associated with both the device group and the device?
The policy remains applied to the device through the direct device association. Removing the device from the device group removes the group-based association only.
Will a newly added device-level policy remain after the device is removed from the group?
Yes. A policy directly associated with the individual device remains on the device even after the device is removed from a device group.
Should this be tested before using it on production devices?
Yes. Test the workflow on a test device first to confirm that the required policies and configurations remain applied as expected.