Category filter

Manage user accounts on Mac

Effectively managing multiple user accounts on a single device is of utmost importance to fulfilling a company’s various security policies. Even though having multiple users on a single device can help a company allocate its resources more effectively, if not managed properly, it can lead to unauthorized logins and data breaches. Well, now with Hexnode, you can manage all user accounts on your Mac seamlessly. Create an account, change the password, grant a secure token, disable a user or keep track of the local account information, including the last login session.

Note:


The device should have the latest version of the Hexnode Agent app installed.

How to remotely manage local users on Mac?

Hexnode UEM offers you a variety of options to manage local accounts on your Mac remotely.

Sync Local Accounts

Note:


The Sync Local Accounts action is available only on the Ultimate and Ultra plans.

This action helps you to sync all the user accounts on your Mac into Hexnode UEM.

  1. Log in to the Hexnode UEM console.
  2. Navigate to the Manage tab and click on the name of the macOS device whose local accounts you want to display.
  3. Click on Actions and choose Sync Local Accounts.
  4. Now click on the Local Accounts tab.

Here you can see a list of all the active users on the macOS device, along with other parameters such as:

  • Role: displays whether a user is an Administrator or a Standard user.
  • User ID: displays the numerical ID of a user.
  • Secure Token: displays whether the Secure Token has been granted to the user.
  • Account Type: displays whether the user is a local user or network user.
  • Status: displays whether the user is currently logged in or logged out.

You can also view inactive or deleted users by clicking on the ‘Show Inactive/Deleted Users’ button situated at the bottom of the user accounts list.
List of all active/inactive user accounts on a Mac

Clicking on the name of a user will give you additional details like:

  • Full name: displays the full name of the user.
  • User name: displays the username of the user.
  • Aliases: displays the short-hand version of the user’s account name that can be used to sign in.
  • Account type: specifies whether the user is an Admin user or Standard user.
  • Apple ID: displays the Apple ID associated with the device.
  • Unique ID (UID): displays the unique ID assigned to the user by the device.
  • Generated Unique ID (GUID): displays a 128-bit identifier assigned to the Mac.
  • Login shell: displays the details of the Login shell on the device.
  • Home directory path: displays the location of the home folder of the user.
  • User created time: displays the date and time when the user was created.
  • Password last changed on: displays the date and time when the account password was last modified.
  • Password hint: displays the hint of the password of the user.
  • Last successful login: displays the date and time of the last successful login of the user.
  • Last failed login: displays the date and time of the last unsuccessful login of the user.
  • Failed login attempts: displays the number of failed login attempts that occurred after the last successful login.
  • Hidden account: displays whether the account is hidden on the Mac.
  • Secure Token status: displays whether the Secure Token has been granted to the user.
  • Account login picture path: displays the path of the user account image.

Details of a user account on a Mac

Create User Account

Note:


The Create User Account action is available only on the Ultimate and Ultra plans.

This action helps you to create a new local user account on your Mac device.

  1. Log in to your Hexnode portal.
  2. Navigate to Manage > Devices.
  3. Select the macOS device to which you want to add a new user.
  4. Click the Local Accounts tab and click the Add User icon.
  5. A dialog box opens up. Here you can configure various settings, such as:
    • Account Name
    • Password
    • Password Hint
    • Account Type
    • Secure Token
    • Aliases
    • Hide account from Login Window and Users & Groups

Take a look at our detailed guide on how to create user accounts on macOS devices.

OR

  1. Navigate to Manage > Devices.
  2. Select the macOS device to which you want to add a new user.
  3. Click Actions > Create User Account.
  4. Configure various settings as mentioned above.

Create a new user account via the Actions tab

Grant Secure Token

Note:


The Grant Secure Token action is available only on the Ultimate and Ultra plans.

This action will grant the Secure Token to a user on your Mac.

  1. Navigate to Manage > Devices.
  2. Select the macOS device to whose user account(s) you want to grant the Secure Token.
  3. Click the Local Accounts tab.
  4. Locate the user to whom you want to grant the Secure Token and check if the token has already been granted under the Secure Token column.
  5. If not, click on the horizontal three-dot menu and choose the Grant Secure Token option.
  6. Under the Administrator account details, enter the credentials of the admin user account, for which the secure token has already been enabled.
  7. Under the Target account details, enter the password of the user account for which the Secure Token is to be enabled. You can make use of wildcards to automatically populate the corresponding fields from the data provided during device enrollment.
  8. Click Proceed in the confirmation dialog box.
  9. Click Confirm to grant the Secure Token to the user.
OR
  1. Navigate to Manage > Devices.
  2. Select the macOS device whose user account you want to grant the Secure Token.
  3. Click the Actions tab.
  4. Choose Grant Secure Token.
  5. Under the Administrator account details, enter the credentials of the admin user account, for which the secure token has already been enabled.
  6. Under the Target account details, enter the credentials of the user account for which the Secure Token is to be enabled. You can make use of wildcards to automatically populate the corresponding fields from the data provided during device enrollment.
  7. Click on Grant Token.

Grant Secure Token to a user account on a Mac

Refer to this doc for more detailed information on how to grant a Secure Token to a user account on Mac.

Force Log Out User

Note:


The Force Log Out User action is available only on the Ultra plan.

This action will log the user out of their currently logged-in session.

  1. Navigate to Manage > Devices.
  2. Select the macOS device whose user account you want to force log out.
  3. Click the Local Accounts tab.
  4. Click the Power button icon corresponding to the user that you want to force log out which is situated to the left of the horizontal three-button menu.
  5. Click Proceed in the confirmation dialog box.
  6. Click Confirm to force log out the user.
OR
  1. Navigate to Manage > Devices.
  2. Select the macOS device whose user account(s) you want to force log out.
  3. Click the Local Accounts tab.
  4. Click the name of the user that you want to force log out under the Local Accounts tab.
  5. Click the Actions button and choose the Force Log Out User option.
  6. Click Confirm to force log out the user.

force log out a user on a Mac

Unlock User Account

Note:

  • The Unlock User Account action is available only on the Ultra plan.
  • This action is only supported on devices running macOS 10.13 or later.

This action helps you unlock user accounts that had been locked due to many failed password attempts.

  1. Navigate to Manage > Devices.
  2. Select the macOS device whose user account(s) you want to unlock.
  3. Click the Local Accounts tab.
  4. Click the name of the user that you want to unlock.
  5. Click Actions and choose the Unlock User Account option.
  6. Click Proceed in the confirmation dialog box.
  7. Click Confirm to unlock the user.
OR
  1. Navigate to Manage > Devices.
  2. Select the macOS device whose user account(s) you want to unlock.
  3. Click the Local Accounts tab.
  4. Click the horizontal three-dot menu corresponding to the respective user.
  5. Click the Unlock User Account option from the drop-down menu.
  6. Click Proceed in the confirmation dialog box.
  7. Click Confirm to unlock the user.

Unlock a user account on a Mac

Change User Role

Note:


The Change User Role action is available only on the Ultra plan.

This action helps you change the role of a user to an Administrator or a Standard user.

  1. Navigate to Manage > Devices.
  2. Select the macOS device whose user account(s) role you want to change.
  3. Click the Local Accounts tab.
  4. Click on the name of the user for whom you want to change the role.
  5. Click Actions and choose the Change User Role option.
  6. In the Change User Account Role page, the new role to be assigned for the user will be mentioned. Click on Proceed.
  7. Click Confirm to change the user role.

OR
  1. Navigate to Manage > Devices.
  2. Select the macOS device whose user account(s) role you want to change.
  3. Click the Local Accounts tab.
  4. Click the horizontal three-dot menu corresponding to the respective user.
  5. Click the Change User Role option.
  6. In the Change User Account Role page, the new role to be assigned for the user will be mentioned. Click on Proceed.
  7. Click Confirm to change the user role.

Change the role of a user account on a Mac

Change Password

Note:


The Change Password action is available only on the Ultra plan.

This action will help you change the password for the user. You will require the admin user’s credentials to execute this action.

  1. Navigate to Manage > Devices.
  2. Select the macOS device whose user account(s) password you want to change.
  3. Click the Local Accounts tab.
  4. Click the name of the user to which you want to change the password.
  5. Click Actions and choose the Change Password option.
  6. Provide the username and password of an admin user under Administrator account credentials.
  7. Type in your new password and password hint under Target account details and click Proceed.
  8. Click Confirm to change the password of the user.

OR

  1. Navigate to Manage > Devices.
  2. Select the macOS device whose user account(s) password you want to change.
  3. Click the Local Accounts tab.
  4. Click the horizontal three-dot menu corresponding to the respective user.
  5. Choose the Change Password option from the drop-down menu.
  6. Provide the username and password of an admin user under Administrator account credentials.
  7. Type in the new password and password hint for the target user under Target account details and click Proceed.
  8. Click Confirm to change the password of the user.

change the password of a user account on a Mac

Note:


When setting a password with special characters, it is recommended to exclude characters like ¡, ™, £, ¢, ∞, §, ¶, •, ª, º, –, ≠, «, ‘, “, æ, …, ÷, ≥, ≤.

Disable User

Note:


The Disable User action is available only on the Ultra plan.

This action helps you disable a user temporarily from accessing the device.

  1. Navigate to Manage > Devices.
  2. Select the macOS device whose user account(s) you want to disable.
  3. Click the Local Accounts tab.
  4. Click on the name of the user that you want to disable.
  5. Click Actions and choose the Disable User option.
  6. Click Proceed in the confirmation dialog box.
  7. Click Confirm to disable the user.

OR
  1. Navigate to Manage > Devices.
  2. Select the macOS device whose user account(s) you want to disable.
  3. Click the Local Accounts tab.
  4. Click the horizontal three-dot menu corresponding to the respective user.
  5. Click the Disable User option from the drop-down menu.
  6. Click Proceed in the confirmation dialog box.
  7. Click Confirm to disable the user.

A disabled user can access their device only if the IT Admin enables them from the portal.
disable a user account on a Mac

Enable User

Note:


The Enable User action is available only on the Ultra plan.

This action helps you to enable a user account that is disabled using the Disable User action.

  1. Navigate to Manage > Devices.
  2. Select the macOS device whose user account(s) you want to enable.
  3. Click the Local Accounts tab.
  4. Click on the name of the user that you want to enable.
  5. Click Actions and choose the Enable User option.
  6. Click Proceed in the confirmation dialog box.
  7. Click Confirm to enable the user.

OR

  1. Navigate to Manage > Devices.
  2. Select the macOS device whose user account(s) you want to enable.
  3. Click the Local Accounts tab.
  4. Click the horizontal three-dot menu corresponding to the respective user.
  5. Click the Enable User option from the drop-down menu.
  6. Click Proceed in the confirmation dialog box.
  7. Click Confirm to enable the user.

enable a user account on a Mac

Delete User

This action helps you delete a user on the device.

Note:

  • The Delete User action is available only on the Ultra plan.
  • The user should be logged out before the action can be executed.

  1. Navigate to Manage > Devices.
  2. Select the macOS device whose user account(s) you want to delete.
  3. Click the Local Accounts tab.
  4. Click on the name of the user that you want to delete.
  5. Click Actions and choose the Delete User option.
  6. Click Proceed in the confirmation dialog box.
  7. Click Confirm to delete the user.

OR

  1. Navigate to Manage > Devices.
  2. Select the macOS device whose user account(s) you want to delete.
  3. Click the Local Accounts tab.
  4. Click the horizontal three-dot menu corresponding to the respective user.
  5. Click the Delete User option from the drop-down menu.
  6. Click Proceed in the confirmation dialog box.
  7. Click Confirm to delete the user.

delete a user account on a Mac

Report of Local Accounts on macOS devices

Note:

The activity report of all user accounts on macOS devices is available only on the Ultimate and Ultra plans.

Hexnode easily enables you to fetch a report detailing all the user accounts on the different macOS devices enrolled in Hexnode UEM. It gives you insights on the session type, sync date, login and logout time, session duration, and much more about each local user account on your macOS device. You can get this report by navigating to Reports > Device Reports > Local Accounts (macOS).

Report of all local user accounts on a macOS device

  • Managing Mac Devices