# Sync Local Accounts on macOS devices with Hexnode

The **Sync Local Accounts** action allows IT administrators to remotely audit and refresh the list of user profiles on a managed Mac, providing real-time visibility into account roles, security tokens, and login history.

**Why Sync macOS Local Accounts?**
----------------------------------

Monitoring local user accounts is vital for maintaining security compliance and administrative oversight. Syncing ensures that the Hexnode UEM console accurately reflects the current state of all users on a device, including newly created, inactive, or unauthorized accounts.

- **Security Auditing:** Verify which users possess a **Secure Token** for FileVault access.
- **Privilege Management:** Identify if a user is an **Administrator** or a **Standard** user.
- **Activity Monitoring:** Track the last successful login, failed attempts, and password changes.

**How to Sync Local User Accounts**
-----------------------------------

Administrators can initiate a full synchronization via remote actions or refresh existing data directly from the device summary.

### **Method 1: Using Remote Action (Primary Sync)**

1. Log in to the **Hexnode UEM portal**.
2. Navigate to the **Manage** tab and click on the target **macOS device**.
3. Click on **Actions > Policies & Accounts > Sync Local Accounts**.
4. Navigate to the **Local Accounts** sub-tab to view the updated list.

 Note: 
The **Last Synced** timestamp updates upon successful execution.

 

### **Method 2: Refreshing from the Local Accounts Sub-tab**

1. Navigate to the **Manage** tab and select the macOS device.
2. Open the **Local Accounts** sub-tab.
3. Click the **Sync Icon** (circular arrow) in the top-right corner to update existing account details.

**Understanding Account Attributes**
------------------------------------

The **Local Accounts** sub-tab provides a high-level overview of the following user attributes:

AttributeDescriptionAccount NameThe user name configured on the device.RoleSpecifies the privilege level: **Administrator** or **Standard**.User IDThe unique numerical ID assigned by the macOS system.Secure TokenIndicates if a **Secure Token** is granted (required for FileVault).Account TypeClassified as Local, Network, Mobile, or Guest Account.StatusCurrent state: Logged in, Logged off, or Inactive.**Viewing Additional Account details**
--------------------------------------

For granular troubleshooting, administrators can access the **Local Accounts Details** page by clicking on any specific **Account Name**.

FieldTechnical DetailFull Name / AliasesThe user’s complete name and shorthand login versions.GUIDA unique 128-bit text string (Generated Unique ID) for the account.Login Shell & Home PathThe specific shell (e.g., /bin/zsh) and home directory location.Security StatusSecure Token status and whether the account is **Hidden**.Password MetadataTimestamp of the last password change and the configured **Password Hint**.Login ActivityTimestamps for the last successful/failed logins and count of failed attempts.**Managing Inactive and Deleted Users**
---------------------------------------

Hexnode retains historical data for accounts that are no longer active or have been removed from the system.

1. Open the **Local Accounts** sub-tab for the device.
2. Scroll to the end of the user list.
3. Click **Show Inactive/Deleted Users**.

 Note: 
You can still access the Details page for deleted users to review their previous configurations.

 

**Troubleshooting Guides**
--------------------------

ProblemPotential Root CauseResolutionAccount details are outdatedThe sync action was not executed after a system change.Manual Refresh Required: Always execute **Sync Local Accounts** after modifying passwords or roles.Secure Token status is “No”The user was created without a bootstrap token.Use the **Grant Secure Token** action to link the user to the system’s chain of trust.New account not appearingThe device is offline or the Hexnode Agent is inactive.Ensure the device is online and the latest **Hexnode Agent** is running before re-triggering the sync.Action fails on executionManagement profile issues.Verify that the MDM profile is still valid and that the device hasn’t been locally disenrolled.**Frequently Asked Questions (FAQs)**
-------------------------------------

### **How often should local accounts be synced?**

It is a best practice to execute a sync immediately after performing any account management action (e.g., creating a user or resetting a password) to ensure the portal displays the current state.

### **Can the actual password be seen in the sync details?**

No. For security reasons, Hexnode only displays the **Password Hint** and the timestamp of the last change, never the plain-text password.

### **What is the difference between a “Mobile” and “Local” account?**

A **Local** account exists only on the specific Mac’s disk. A **Mobile** account is a network account (like Active Directory) that has been cached locally to allow offline login.

### **Why do some users show a status of “Inactive”?**

An account is marked as **Inactive** if it has not been used for a significant period or if the account has been disabled via system settings.