# How to Create a Geofencing Policy to Lock Devices Outside the Office

Overview 
---------

Geofencing is a powerful security feature that allows IT administrators to create virtual geographic boundaries. By implementing a geofencing policy, you can ensure that corporate-owned devices remain functional only within a designated area (like your office). In Hexnode UEM, automatically locking a device when it crosses the perimeter requires a three-part approach: defining the Geofence, marking boundary exits as a Compliance violation, and triggering an Automation rule. This is an essential strategy for preventing data breaches due to hardware theft or unauthorized off-site usage.

### Prerequisites 

To implement geofencing effectively, ensure the following:

- **Location Services**: Must be enabled on the target devices.
- **Hexnode App Permissions**: The Hexnode UEM app must have “Always” location access (iOS) or “Allow all the time” (Android).
- **Supported Platforms**: iOS, Android, Windows, and macOS devices.

Step 1: Create a Geofence (The Virtual Boundary) 
-------------------------------------------------

Before creating a policy, you must define the physical coordinates of your office.

1. Log in to your Hexnode UEM Portal.
2. Navigate to **Admin > [Geofencing](https://www.hexnode.com/mobile-device-management/help/geofencing-location-based-mdm-restriction/#creating-a-geofence-region)**.
3. Click **Create Fence**.
4. **Set the Location**: Type your office address in the search bar.
5. **Choose a Shape**: Select either **Polygon** (to trace an exact building outline) or Circle.
6. **Define the Radius**: If using a circle, set a radius (in meters) around the location. Hexnode supports a radius between 100 and 6500 meters. For a standard office, a radius of 100–200 meters is recommended to account for GPS drift.
7. **Provide a Name**: Enter a name in the Fence Name field (e.g., “Main Office HQ”).
8. Click **Save**.

Step 2: Assign the Geofence to Devices 
---------------------------------------

You must apply the geofence to your devices so Hexnode begins tracking their location relative to the boundary.

1. Navigate to the **Policies** tab.
2. Click **New Policy** and provide a name (e.g., “Office Perimeter Policy”).
3. Go to **Tracking and Fencing > [Geofencing](https://www.hexnode.com/mobile-device-management/help/geofencing-location-based-mdm-restriction/#applying-the-geofence-policy)**.
4. Click **+ Add Fence** and select the “Main Office HQ” fence you created in Step 1.
[![Device report exported in PDF format of a device group.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2026/05/Configure-Geofencing-Policy-to-Lock-Devices-for-Location-Based-Compliance-in-Hexnode-UEM.png "Device report of a device group")](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2026/05/Configure-Geofencing-Policy-to-Lock-Devices-for-Location-Based-Compliance-in-Hexnode-UEM.png)

6. Click **OK**.
7. Go to the **Policy Targets** tab, select the Devices, Users, or Device Groups that should be monitored, and click **Save**.

Step 3: Define the Rules of Engagement (Compliance) 
----------------------------------------------------

Geofencing alone just tells the system where the device is. You must instruct Hexnode that leaving the fence is a critical security violation.

1. Go to **Policies > [Compliance Policies](https://www.hexnode.com/mobile-device-management/help/how-to-create-a-compliance-policy-for-devices/) > New Policy**.
2. Select your target platforms.
3. Under **Basic Settings**, check the box for **Device moves out of geofence**.
[![Screenshot of the Hexnode UEM console showing the Compliance Policies section within the Policies tab. A new policy is being configured for the target platforms where the checkbox for Device moves out of geofence is selected under the Basic Settings menu to enforce a Geofencing Policy to Lock Devices.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2026/05/Setting-Up-a-Geofencing-Policy-to-Lock-Devices-in-Hexnode-UEM.png "Device report of a device group")](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2026/05/Setting-Up-a-Geofencing-Policy-to-Lock-Devices-in-Hexnode-UEM.png)

5. Navigate to **Policy Targets**, apply this to the same devices/groups from Step 2, and click Save.

 Note:The moment a device leaves the area, it will now be marked as “Non-Compliant” in the Hexnode portal

 

Step 4: Automate the Device Lock 
---------------------------------

Now, you configure Hexnode to automatically lock the device the moment it becomes non-compliant due to location.

1. Navigate to the **[Automate](https://www.hexnode.com/mobile-device-management/help/automate-device-management-tasks/)** tab and click **New Automation**.
2. Name the automation (e.g., “Defensive Lock: Office Exit”).
3. **The Trigger**: Set the automation to trigger based on Activity and specifically select **On Location Non-Compliance**.
4. **The Action**: Scroll to the Security actions section and choose your response:
1. **[Lock Device (Standard)](https://www.hexnode.com/mobile-device-management/help/lock-a-device-using-hexnode-mdm/)**: Sends the device to the standard lock screen, securing it behind the user’s existing passcode or biometric.
2. **[Enable Lost Mode (Strict)](https://www.hexnode.com/mobile-device-management/help/lost-mode-for-macos/)**: Completely freezes the user out of the hardware, overrides their normal PIN, and can display a custom security warning on the screen.

6. Target this automation at your high-security device groups and activate it.

How to Regain Access 
---------------------

If a device is locked because it left the geofence, how you regain access depends on the strictness of the action you chose in Step 4:

- **Standard Device Lock**: The screen simply turns black and locks. The employee can unlock the device locally by entering their standard PIN, passcode, or using biometrics.
- **Lost Mode**: The device is effectively a brick. An administrator must log into the Hexnode portal, go to **Manage > Devices**, select the locked device, and trigger the **Disable Lost Mode** remote action.

Best Practices for Geofencing 
------------------------------

- **Test the Radius**: Start with a slightly larger radius to avoid “false positives” where the device locks while the user is simply near a window or in the parking lot.
- **Battery Impact**: Frequent location reporting can impact battery life. Balance the Location Update Interval by navigating to **Policies > New Policy > Create a fully custom policy > [Platform] > Tracking and Fencing > [Location Tracking](https://www.hexnode.com/mobile-device-management/help/how-to-configure-location-tracking-with-hexnode-mdm/#periodic-location-tracking)** based on your security needs (Hexnode allows intervals ranging from 15 minutes to 24 hours).
[![Screenshot of the Hexnode UEM console showing the Policies tab during the creation of a new fully custom policy. The Location Tracking option is selected from the Tracking and Fencing category in the left-hand menu, displaying configuration settings to manage the update interval as part of a Geofencing Policy to Lock Devices.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2026/05/Balance-Location-Update-Interval-for-a-Geofencing-Policy-to-Lock-Devices-in-Hexnode-UEM.png "Balance Location Update Interval for a Geofencing Policy to Lock Devices in Hexnode UEM")](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2026/05/Balance-Location-Update-Interval-for-a-Geofencing-Policy-to-Lock-Devices-in-Hexnode-UEM.png)

- **Notify Employees**: Transparency is key. Inform users that their devices are geofenced to avoid confusion and support tickets when devices lock unexpectedly.