# Co-management of Windows devices

**Windows 10 Co-management** is a configuration that enables the concurrent management of devices running Windows 10 or later that are already enrolled in a third-party UEM solution.

While a device enrolled in another UEM/MDM cannot be fully enrolled in Hexnode simultaneously, co-management allows Hexnode to coexist on the device. This provides conditional access to Hexnode’s management functionalities, allowing administrators to fetch device details, deploy automations, and perform remote actions. This is often used as a primary method to streamline migration from other vendors to Hexnode.

Supported Platforms 
--------------------

Co-management is supported on the following operating systems:

- **Windows 10 v1803+**
- **Windows 10 v1703** to **Windows 10 v1709** (requires .NET Framework v4.7.1+ installed)
- **Windows 11**

How Windows Co-management Works 
--------------------------------

Co-management allows two management authorities to reside on a single device. The process follows this logic:

1. **Detection**: When the Hexnode Installer is run, it checks if the device is managed by another UEM.
2. **Verification**: If a third-party UEM is detected and Co-management is enabled in the Hexnode portal, the user is offered the option to co-manage.
3. **Status**: A co-managed device displays an **Enrolled (Limited)** status under **Device Summary > Enrollment details**. Available data is confined to *Device Summary, Device Info, Applications, Device Groups, and Action History*.

Step 1: Enable Co-management in Hexnode Portal 
-----------------------------------------------

Before users can enroll, an administrator must enable the feature in the enrollment profile.

1. Log in to your **Hexnode UEM** console.
2. Navigate to **Enroll > Platform-Specific > Windows PCs & Tablets > Information**.
3. Under **Enrollment profile**, select an existing profile and click **View**.
4. Go to **General Settings** and locate the **Co-management** section.
5. Click the **Enabled** button.

Step 2: Enrollment Instructions for the User 
---------------------------------------------

Once enabled, the user can initiate co-management directly from the device:

1. Open a web browser on the Windows device and enter your organization’s **enrollment URL**.
2. Click **Download** to get the Hexnode Installer app.
3. Open the downloaded file to install the app.
4. Launch the app and tap **Agree** and **Enroll** (after reviewing the EULA).
5. Click **Proceed** to initiate co-management.
6. If **Authenticated Enrollment** is required, enter your credentials in the Authentication window.
7. Follow the on-screen prompts to install the agent and complete the setup.

![enroll devices with limited device management capabilities](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2021/11/enrollment-status-for-co-managed-devices.png "enrollment status for co-managed devices")

Remote Actions for Co-managed Devices 
--------------------------------------

Even with limited enrollment status, Hexnode allows you to execute a wide range of remote actions on co-managed Windows devices:

**Scanning**: [Scan Device](https://www.hexnode.com/mobile-device-management/help/scan-devices-remotely-using-hexnode-mdm/), [Scan for Updates](https://www.hexnode.com/mobile-device-management/help/how-to-scan-for-windows-updates-on-devices-from-hexnode/), [Scan for Apps ](https://www.hexnode.com/mobile-device-management/help/how-to-remotely-scan-applications-on-devices-using-hexnode-uem/), [Scan Device Location](https://www.hexnode.com/mobile-device-management/help/how-to-scan-device-location-using-hexnode-mdm/).

**Security**: [Lock Device](https://www.hexnode.com/mobile-device-management/help/lock-a-device-using-hexnode-mdm/), [Wipe Device](https://www.hexnode.com/mobile-device-management/help/wipe-a-device-completely-using-hexnode-mdm/), [ Force BitLocker Encryption](https://www.hexnode.com/mobile-device-management/help/how-to-force-bitlocker-encryption-on-windows-with-hexnode-uem/), [ Enable Lost Mode](https://www.hexnode.com/mobile-device-management/help/how-to-enable-lost-mode-for-windows-10-pcs/), [ Disable Lost Mode](https://www.hexnode.com/mobile-device-management/help/how-to-enable-lost-mode-for-windows-10-pcs/#disabling-lost-mode-on-windows-devices).

**Management**: [Power off Device](https://www.hexnode.com/mobile-device-management/help/turn-a-device-off-using-hexnode-mdm/), [Restart Device](https://www.hexnode.com/mobile-device-management/help/restart-a-device-using-hexnode-mdm/), [Join/Unjoin AD Domain](https://www.hexnode.com/mobile-device-management/help/how-to-remotely-join-unjoin-ad-domain-on-windows-devices/), [ Change Owner](https://www.hexnode.com/mobile-device-management/help/assign-a-device-to-a-new-user-using-hexnode-mdm/), [ Set Friendly Name](https://www.hexnode.com/mobile-device-management/help/rename-a-device-or-set-friendly-name-using-hexnode-mdm/), [ Change Ownership](https://www.hexnode.com/mobile-device-management/help/how-to-change-the-ownership-of-a-device-using-hexnode/).

**Application and User Management**: [ Install Application](https://www.hexnode.com/mobile-device-management/help/distribute-enterprise-apps-msi-to-windows-10-devices/#), [Uninstall Application](https://www.hexnode.com/mobile-device-management/help/remove-apps-from-windows-devices/), [Create User Account](https://www.hexnode.com/mobile-device-management/help/create-user-account-on-windows-devices-enrolled-in-hexnode-uem/), [Sync Local Accounts](https://www.hexnode.com/mobile-device-management/help/sync-user-accounts-on-macos-devices-with-hexnode/) .

**Location**: [Enable Location Tracking](https://www.hexnode.com/mobile-device-management/help/how-to-configure-location-tracking-with-hexnode-mdm/), [Delete Location History](https://www.hexnode.com/mobile-device-management/help/how-to-delete-a-devices-location-history-retained-in-hexnode-uem/).

**Utilities**: [Broadcast message](https://www.hexnode.com/mobile-device-management/help/broadcast-messages-to-a-device-enrolled-in-hexnode-mdm/), [Execute Custom Script](https://www.hexnode.com/mobile-device-management/help/executing-custom-scripts-for-windows/), [Edit Device Attributes](https://www.hexnode.com/mobile-device-management/help/how-to-remotely-modify-device-attributes/), [ Export Device Details](https://www.hexnode.com/mobile-device-management/help/how-to-export-device-details-using-hexnode-mdm/).

**Termination**: [ Disenroll Device](https://www.hexnode.com/mobile-device-management/help/disenroll-and-delete-device-from-hexnode-mdm/#).

Advanced Co-management Features 
--------------------------------

### Remote View and Control 

Hexnode enables real-time [Remote View](https://www.hexnode.com/mobile-device-management/help/how-to-enable-remote-view-for-windows-10-devices/) and **Remote Control** for co-managed devices. The Hexnode Remote Assist application, installed during enrollment, facilitates [unattended remote access](https://www.hexnode.com/mobile-device-management/help/how-to-enable-remote-view-for-windows-10-devices/), allowing admins to view the screen and control the device directly from the portal.

![Initiating Remote View.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2021/06/Remote-View_Assist.png)

### Patch Management and Updates 

Manage OS and application updates over-the-air via the [Patches](https://www.hexnode.com/mobile-device-management/help/patches-and-updates-deployment/) tab. You can monitor available updates and choose to deploy them either [automatically](https://www.hexnode.com/mobile-device-management/help/automated-patch-management-windows/) or [manually](https://www.hexnode.com/mobile-device-management/help/manual-patch-deployment-windows/).

![Automate deployments on device through Patches and Updates.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2021/06/Patches-and-Updates.png)

### Automation 

Schedule bulk actions or trigger deployments based on device behavior (e.g., enrollment or compliance status) via the [Automate](https://www.hexnode.com/mobile-device-management/help/automate-device-management-tasks/) tab. Supported automated actions include:

- **[Execute Custom Script](https://www.hexnode.com/mobile-device-management/help/executing-custom-scripts-for-windows/)**
- **[Scan Device](https://www.hexnode.com/mobile-device-management/help/scan-devices-remotely-using-hexnode-mdm/)**
- **[Sync Local Accounts](https://www.hexnode.com/mobile-device-management/help/sync-user-accounts-on-macos-devices-with-hexnode/)**
- **[Scan Device Location](https://www.hexnode.com/mobile-device-management/help/how-to-scan-device-location-using-hexnode-mdm/)**
- **[Broadcast message](https://www.hexnode.com/mobile-device-management/help/broadcast-messages-to-a-device-enrolled-in-hexnode-mdm/)**
- **[Power off Device](https://www.hexnode.com/mobile-device-management/help/turn-a-device-off-using-hexnode-mdm/)**
- **[Restart Device](https://www.hexnode.com/mobile-device-management/help/restart-a-device-using-hexnode-mdm/)**
- **[Lock Device](https://www.hexnode.com/mobile-device-management/help/lock-a-device-using-hexnode-mdm/)**
- **[ Enable Lost Mode](https://www.hexnode.com/mobile-device-management/help/how-to-enable-lost-mode-for-windows-10-pcs/)**
- **[ Disable Lost Mode](https://www.hexnode.com/mobile-device-management/help/how-to-enable-lost-mode-for-windows-10-pcs/#disabling-lost-mode-on-windows-devices)**

![Creating a new deployment through the Automate tab in Hexnode UEM.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2021/06/Automate-tab-in-Hexnode-UEM.png)

Local User Account Management 
------------------------------

Manage local accounts via the **Local Accounts** sub-tab. Capabilities include:

- **[Create new user accounts](https://www.hexnode.com/mobile-device-management/help/create-user-account-on-windows-devices-enrolled-in-hexnode-uem/)**
- **[Change password](https://www.hexnode.com/mobile-device-management/help/change-windows-local-account-password/)**
- **[Change user role to standard user or administrator](https://www.hexnode.com/mobile-device-management/help/manage-local-user-accounts-of-windows-devices-enrolled-in-hexnode-uem/#change-user-role)**
- **[Sync user accounts with the Hexnode portal](https://www.hexnode.com/mobile-device-management/help/sync-user-accounts-on-macos-devices-with-hexnode/)**
- **[Disable/enable user accounts](https://www.hexnode.com/mobile-device-management/help/manage-local-user-accounts-of-windows-devices-enrolled-in-hexnode-uem/#disable-account)**
- [**Delete user accounts**](https://www.hexnode.com/mobile-device-management/help/manage-local-user-accounts-of-windows-devices-enrolled-in-hexnode-uem/#delete-account)
- **[Force logout a user](https://www.hexnode.com/mobile-device-management/help/manage-local-user-accounts-of-windows-devices-enrolled-in-hexnode-uem/#force-log-out-user)**

To ensure the Hexnode portal reflects the most current user data, execute the **Sync Local Accounts** remote action on the device.

Once synchronized, you can view and manage these accounts via the portal:

- Navigate to the specific **Device Details** page of the co-managed device.
- Select the **Local Accounts** sub-tab.

![Managing local user accounts in a co-managed Windows device.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2021/06/Local-User-Accounts-in-Windows.png)

Policies supported on Co-Managed Devices
----------------------------------------

Configure and deploy essential device settings, security protocols, and app management rules directly through the **Policies** tab. Hexnode lets you configure the following policies:

**App Management:** [App Catalog](https://www.hexnode.com/mobile-device-management/help/how-to-create-app-catalog-for-windows-devices/)

**Security:** [Hexnode Access,](https://www.hexnode.com/mobile-device-management/help/set-up-hexnode-access-to-allow-login-to-windows-using-idps/) [Hexnode LAPS](https://www.hexnode.com/mobile-device-management/help/windows-laps-policy/)

**Configurations:** [Scripts,](https://www.hexnode.com/mobile-device-management/help/how-to-execute-custom-scripts-periodically-on-windows/) [Wallpaper,](https://www.hexnode.com/mobile-device-management/help/how-to-set-wallpaper-on-windows-devices/) [Screensaver,](https://www.hexnode.com/mobile-device-management/help/configure-screensaver-settings-for-windows-devices/) [Browser Settings,](https://www.hexnode.com/mobile-device-management/help/how-to-configure-browser-settings-on-windows-devices/) [Self Service](https://www.hexnode.com/mobile-device-management/help/self-service-windows-users/)

**Patches & Updates:** [Windows Update Experience](https://www.hexnode.com/mobile-device-management/help/configure-windows-update-end-user-experience/) (Patch maintenance window, and active hours configuration), [App Updates](https://www.hexnode.com/mobile-device-management/help/configure-app-patches-for-windows-devices-using-hexnode-uem/)

**Tracking & Fencing:** [Geofencing](https://www.hexnode.com/mobile-device-management/help/geofencing-location-based-mdm-restriction/)

**Troubleshooting:** [Unattended Remote Access](https://www.hexnode.com/mobile-device-management/help/allow-unattended-access-to-remotely-view-and-control-devices-with-hexnode-uem/)

**Customizations:** [Hexnode App Settings](https://www.hexnode.com/mobile-device-management/help/hexnode-app-settings/)

**Hexnode Settings:** [DAFS](https://www.hexnode.com/mobile-device-management/help/distribution-server-for-windows/)

Migration: Fully Enrolling a Co-Managed Device 
-----------------------------------------------

To unlock all Hexnode features, you may wish to transition from co-management to full enrollment. This requires removing the previous UEM vendor.

### 1. Remove Existing MDM 

1. Open **Settings** on the Windows device.
2. Navigate to **Accounts > Access work or school**.
3. Select the account associated with the *current* (third-party) MDM vendor.
4. Click **Disconnect**.

### 2. Re-enroll in Hexnode 

Rerun the Hexnode Installer or [initiate](https://www.hexnode.com/mobile-device-management/help/how-to-enroll-windows-laptops-in-hexnode-mdm/) enrollment.

- **No Authentication**: The device fully enrolls and is assigned to the current user. Admins can change the owner later.
- **Enforce Authentication**: The device fully enrolls and assigns to the existing owner only if the same user authenticates. If a different user authenticates, enrollment will fail.

Frequently Asked Questions (FAQs) 
----------------------------------

### Q1: When will Co-management enrollment fail? 

Co-management will fail in the following instances:

- **Disabled Feature**: If Co-management is disabled in the **Admin** tab of the portal.
- **Existing Hexnode Enrollment**: If the device is already enrolled in another Hexnode portal.
- **Same Portal Conflict**: If the device is already fully enrolled in the current Hexnode portal. You must disenroll it first before attempting to co-manage.

Troubleshooting 
----------------

### 1. The user is unable to download the Hexnode Installer application when using the enrollment URL (e.g., */enroll*). 

**Symptom**: The download fails, and the user encounters the following error message:

“*According to your corporate policy, only the following device types can be enrolled and can access the corporate resources: iPad, iPhone, iPod, macOS, tvOS and Android. Contact your company’s IT administrator for more information.*”

**Cause**: Enrollment restrictions are active in the Hexnode portal, and **Windows** has not been selected in the list of **Allowed Device Models**. Consequently, the system blocks the download for Windows devices.

**Resolution**:

1. Log in to the **Hexnode UEM** portal.
2. Navigate to A**dmin > Enrollment > Enrollment Restrictions**.
3. Locate the **Device Models allowed** list.
4. Check the box next to **Windows** to allow enrollment for this platform.
5. Save the policy and retry the download.