Category Filter

How to configure self-enrollment?

Device enrollment in the MDM is a process that smoothens the communication between the device and the organization. Enterprises can easily control and limit access to the organizational network, apps, and files on an enrolled device.

Self-Enrollment in Hexnode MDM helps you secure the user enrollment by enforcing authentication. This allows users to enroll their own devices by authenticating with the already known credentials. This exempts the admins from the hassle of enrolling the device by themselves. With Hexnode, you can set-up self-enrollment using Active Directory (AD), Azure AD, Google, Okta, and local user authentication.

Configure self-enrollment for local users

Enable self-enrollment for local users to allow them to enroll their own devices by authenticating their pre-assigned local credentials.

  1. Login to your Hexnode portal.
  2. Go to Enroll > All Enrollments > Enterprise > Self-Enrollment – Local.
  3. Select the option Local User under Self Enrollment.
  4. Change the devices’ Ownership type to either Corporate, Personal, or Let the user choose.
  5. Click on Continue.
  6. To assign/change the password of the local user from the MDM console,

  7. Select the required user/users and click on Change password. Type in the required password and click OK.

If you want to create a new user, click on the option Create a new user and provide the Display name, Domain, Email, Alternate email, Mobile and Password of the user. The display name and email fields are mandatory.

Share this password with the corresponding user. While enrolling devices, the user must provide his email (username) and authenticate with this pre-assigned password.

Apart from assigning passwords to individual users from the MDM console, you can also assign passwords to user’s in Hexnode by importing a CSV file.

Configure self-enrollment for directory users

Enable self-enrollment for directory users to allow then in enrolling their own devices by authenticating with their AD, Azure AD, Google or Okta credentials.

  1. Login to your Hexnode portal.
  2. Go to Enroll > All Enrollments > Enterprise > Self-Enrollment – Local.
  3. Select the required domains (AD/ Azure AD/ Google/ Okta) under Self Enrollment.
  4. Change the devices’ Ownership type to either Corporate, Personal, or Let the user choose.
  5. Click on Continue.

How to enroll devices using self-enrollment?

Enrolling Android devices

Enrolling Android devices

  1. Install the Hexnode MDM application on your device.
  2. Open the app and enter the server name which of the format:portalname.hexnodemdm.com.
  3. Click on Next.
  4. Choose your authentication method (local or directory) and enter the username and password.
  5. Click on Next.
  6. Read and Agree to the End User’s License Agreement.
  7. Enable the Device administration permission, Usage access permission, Draw over apps permission, Write system settings permission, Notification access permission and Allow app installation permission.
  8. Click Next.
  9. Click Allow in the following pop ups which asks for location, storage and phone permissions.
  10. Click on Grant for granting additional permissions like location, calls, etc.
  11. Follow the on-screen instructions to complete enrollment.


You can also self-enroll your devices to the Android Enterprise program either via the Profile Owner or Device Owner enrtollment methods.


Enrolling iOS devices

Enrolling iOS devices

  1. Open Safari on your iOS device and enter the enrollment URL. It is of the format: https://portalname.hexnodemdm.com/enroll/
  2. Check the box “I have read and agree to the terms of the Hexnode MDM” and click Enroll.
  3. If you are a local or AD user, select the domain and enter the local/AD username and password of the user and click Authenticate. If you are a Microsoft/Googe/Okta user, you can authenticate by signing in with the corresponding directory credentials.
  4. Click on Allow to download the configuration profile on the device and click Close.
  5. Go to Settings app on your device. Navigate to General > Profile and open the profile.
  6. Click on Install to install the configuration profile and certificate. This will open up a pop-up tab ‘Install Profile’, click on Install.
  7. The device will warn you that the Hexnode root certificate installation and the MDM management, click on Install.
  8. Click on Trust to enable remote management for Hexnode.
  9. When the profile is installed, click Done.
  10. In the pop up that asks permission to install Hexnode MDM app, click Allow.
  11. Allow the MDM to access location and send notifications.


Enrolling Windows PCs or Tablets

Enrolling Windows PCs or Tablets

On a Windows 10 v1803 or later device,


Enrollment via Hexnode Installer app:

  1. On your Windows 10 device, open the web browser.
  2. Enter the Hexnode enrollment URL. It should be in the format: https://portalname.hexnodemdm.com/enroll/.
  3. Click on Download. This would initiate the Hexnode Installer app download on your device.
  4. Open the app on your device.
  5. Click Yes on the ‘Hexnode Installer Setup’ wizard to allow the Hexnode Installer app to make changes to your device.
  6. Click on Install to continue with the installation.
  7. Read the EULA agreement on the Hexnode Installer app and click on Agree and Enroll.
  8. The Hexnode Installer then checks with the portal for the enrollment authentication settings.
  9. If you are a local or AD user, enter your email ID/SAMAccount Name and click on Authenticate. If you are a Microsoft/Googe/Okta user, you can authenticate by signing in with the corresponding directory credentials. You should also choose the ownership of the device if asked.
  10. If the authentication fails, an error message “Authentication failed! Try Again!” will be displayed. Click on Enroll to re-authenticate.
  11. Now the device will process the enrollment request. If the enrollment request processing fails,
    1. Click on Enroll to enroll the device. This will redirect you to Settings > Accounts > Access Work or Scholl > Enroll in Device Management on your device.
    2. On the ‘Set up a work or school account’ pane, super admin’s Hexnode portal username, and the enrollment server address will be auto-filled, click on Next.
    3. Read the instructions regarding the device set up and click Got it. Hexnode will now connect to the Workplace or School. It may take a few minutes to set up the connection, all the configurations and apps that your organization has set up for the user will soon be pushed to the device. If the user doesn’t have access to these after waiting for a few minutes, go to Settings > Accounts > Access Work or school > Info > Sync.
  12. The Hexnode Agent app (HexnodeAgent) will get installed, and all the configurations will be applied to the device. Click on Done to exit the Hexnode Installer.
  13. Click on Finish to exit the Setup.


On a Windows 10 v1709 or below device,


Native Windows Enrollment:

  1. Go to Settings → Accounts → Access work or school.
  2. Select Enroll only in device management.
  3. Enter your work email and click Next.
  4. Now you will be asked to enter your Microsoft password, simply neglect this by closing the tab.
  5. Enter the server URL, it will be of the format: https://portalname.hexnodemdm.com and click Next.
  6. If you are a local or AD user, select the domain and enter the local/AD username and password of the user and click Authenticate. If you are a Microsoft/Googe/Okta user, you can authenticate by signing in with the corresponding directory credentials.
  7. Read the instructions regrading setting up the device and click Got it. You have now successfully enrolled your PC.


Enrolling macOS devices

Enrolling macOS devices

  1. Open Safari.
  2. Enter the enrollment URL, it will be of the format https://portalname.hexnodemdm.com/enroll/.
  3. Check the box “I have read and agree to the terms of the Hexnode MDM” and click Enroll.
  4. If you are a local or AD user, select the domain, enter the username and password and click Authenticate. If you are an Azure AD, Google or Okta user, click on Authenticate with Microsoft, Google or Okta.
  5. The MDM profile gets downloaded. Click Continue to allow the MDM profile to be configured on the Mac and click Install.
  6. Enter the Mac administrator’s username and password to continue with the installation.