# How to set up Wi-Fi for iOS devices?

Hexnode UEM allows administrators to remotely configure and push Wi-Fi network settings to iOS devices. This ensures devices connect to secure networks automatically without requiring manual user intervention or password disclosure.

Configuration Steps: iOS Wi-Fi Policy
-------------------------------------

To deploy Wi-Fi settings, follow these steps in the Hexnode UEM portal:

1. **Navigate to Policies:** Go to the **Policies** tab.
2. **Create Policy:** Navigate to **New Policy > Create a fully custom policy**.
3. **Access Wi-Fi Settings:** Navigate to **iOS > Network > Wi-Fi** and click **Configure**.
4. **Add Networks:** You can configure multiple Wi-Fi networks within a single policy by clicking the **+Add more** button.

### Wi-Fi Configuration Parameters

**Parameter****Description****Service Set Identifier (SSID)**The unique name of the Wi-Fi network.**Auto join**Allows the device to connect automatically when within range. (Default: Enabled)**Hidden Network**Enable this if the SSID is not broadcasting. (Default: Disabled)**Disable MAC address randomization**Disables MAC address randomization for the specific network. *Note: Supported on iOS 14+.***Security Type**Defines the encryption method (e.g., WEP, WPA/WPA2, WPA3, Enterprise options).**Proxy**Configuration for network proxies (None, Manual, or Automatic).![configure Wi-Fi settings on iOS devices](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2023/09/iOS-Wi-Fi-settings.png "iOS Wi-Fi settings")[](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2023/09/iOS-Wi-Fi-settings.png)

Network Security Types & Requirements
-----------------------------------------

The configuration requirements vary based on the selected Security Type:

### 1. Open and Personal Networks

- **None:** Used for open Wi-Fi networks; no password required.
- **WEP, WPA/WPA2, Any (personal), WPA2/WPA3, or WPA3:** Admins must provide the **Password**. Users will join automatically without seeing or entering the credentials.

### 2. Enterprise Security Options (802.1X)

Used for Enterprise-grade security. Key options include:

**Option****Description****Accepted EAP types**TLS, LEAP, EAP-FAST, TTLS, PEAP, EAP-SIM. (TTLS is accepted by default).**Inner identity**(TTLS only) Authentication processes: PAP (default), CHAP, MS-CHAP, or MS-CHAPv2.**Username**Enterprise network username. Supports the `%username%` wildcard.**Identity certificate**SCEP or PKCS certificate profiles uploaded via **Policies > Security > Certificates**.[![Set up wi-fi network enterprise mobile configuration on iOS devices with MDM](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2023/09/Set-up-Wi-Fi-network-connection-settings-on-iOS-devices-using-MDM.png "Set up Wi-Fi network connection settings on iOS devices using MDM")](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2020/12/set-up-wi-fi-network-connection-settings-on-ios-devices-using-mdm.png)

Proxy Settings
--------------

- **None:** Default state. No proxy server is utilized.
- **Manual:** Requires **Server**, **Port**, and optional **Authentication** details.
- **Automatic:** Requires a **Proxy PAC URL** to the configuration file.

Policy Association and Deployment
---------------------------------

1. In the policy window, go to **Policy Targets**.
2. Select **Devices, Device Groups, Users, User Groups, or Domains**.
3. Choose the specific targets and click **Save**.

### Expected Device Behavior

- **Silent Connection:** The Wi-Fi profile is pushed silently to the device.
- **Automatic Connection:** If “Auto join” is enabled, the device connects immediately when in range.
- **Security:** Users cannot view the stored Wi-Fi password in the device settings.

Frequently Asked Questions (FAQs)
---------------------------------

1. **Can multiple Wi-Fi networks be configured in a single policy?**Yes. By clicking the **+Add more** button, multiple SSIDs can be added to a single policy for seamless transitions between office locations.
2. **Is it possible to prevent users from seeing the Wi-Fi password?**Yes. Credentials are encrypted within the configuration profile. The user can connect, but the password remains hidden.

Troubleshooting
---------------

**Issue****Resolution****Fails to connect to hidden network**Ensure the **Hidden Network** checkbox is enabled in the policy.**Enterprise (802.1X) fails**Verify that the SCEP/PKCS certificate is valid and the Root CA is trusted.**“Unable to join network” error**Confirm the **Security Type** matches the router’s actual configuration.