# Wi-Fi configuration on Windows devices

Configuring **Wi-Fi settings** on devices allows users to access corporate Wi-Fi seamlessly. You can configure the Wi-Fi settings remotely and deploy them to Windows devices. It allows the users to access the organization network automatically without worrying about configuring it manually.

 Note: 
**Supported Versions:**

- Windows 10 (Pro, Enterprise, Education)
- Windows 11 (Pro, Enterprise, Education)

 

 Configure Wi-Fi settings for Windows
-------------------------------------

To create Wi-Fi configuration settings for Windows devices,

1. Login to your Hexnode UEM portal.
2. Navigate to **Policies**. Click on **New Policy** to create a new one or click on any policy to edit an existing one. Enter the *Policy Name* and *Description* in the provided fields.
3. Select **Windows**. Go to **Network > Wi-Fi**. Click on **Configure**
4. The following Wi-Fi network settings can be configured.

Wi-Fi settingsDescriptionService Set IdentifierEnter the name of the Wi-Fi network. It specifies the name of the wireless network the devices get connected.Connection modeSelect the option **Manual** to enable users to choose the Wi-Fi network manually. By default, the *Connection mode* is set to **Auto**, which lets devices to connect to the Wi-Fi network automatically when they are within the range.

Hidden NetworkSelect **Hidden Network** to enable devices to connect to the Wi-Fi network even if it is not broadcasting its SSID. *Disabled* by default.

Security TypeSelect any security protocol used to authenticate the devices: **Open**, **WEP**, **WPA-PSK/WPA2-PSK/WPA3-SAE**, or **WPA/WPA2/WPA3 Enterprise**. By default, the *Security Type* is set to **Open** which specifies no authentication.

Authentication type (If you select **WPA-PSK/WPA2-PSK/WPA3-SAE,** or **WPA/WPA2/WPA3 Enterprise** as the *Security Type*)

Choose the authentication type from **WPA** (default), **WPA2** and **WPA3.**The difference between **WPA** (Wi-Fi Protected Access), **WPA2**, and **WPA3** is the method of encryption used. **WPA** uses **TKIP** (Temporal Key Integrity Protocol) which is a method for checking message integrity whereas **WPA2** uses AES-based **CCMP** (based on stronger AES encryption algorithm) which is a stronger encryption protocol. **WPA3** uses the **AES-based GCMP** (Galois/Counter Mode Protocol), which provides an even higher level of cryptographic strength and security.

Password (If you select **WEP**, **WPA-PSK/WPA2-PSK/WPA3-SAE**, or **WPA/WPA2/WPA3 Enterprise** as the *Security Type*)

Enter the ***Password*** required for the device to get connected to the Wi-Fi network.EAP authentication (If you select WPA/WPA2/WPA3 Enterprise as the *Security Type*)

Select an Extensible Authentication Protocol (EAP) type to authenticate the network connection from **EAP TLS** (default) and **PEAP-MSCHAPv2**.ProxySelect **Manual** to set up the Proxy settings manually. **Proxy** protects the device from attacks by acting as an intermediary between the device and the internet.

By default, the proxy configuration is set to **None**, which lets you skip setting up a proxy server.

Server (If you choose to set up the *Proxy* settings manually)

Enter the *name* or *IP address* of the *proxy server*.Port (If you choose to set up the *Proxy* settings manually)

Enter the *port number* of the *proxy server*.
By default, the port number is set to 0.[![Wi-Fi configuration settings for Windows devices](https:2020/12/Wi-Fi-configuration-settings-for-Windows-devices.png "Wi-Fi configuration settings for Windows devices")](https:2020/12/Wi-Fi-configuration-settings-for-Windows-devices.png)

 Exception: The policy is not applied if the device is already connected to the Wi-Fi network being configured.

 

 Apply the Wi-Fi network policy to devices/groups
-------------------------------------------------

There are two ways by which you can associate restrictions to the devices in bulk.

If you haven’t saved the policy yet,

1. Navigate to **Policy Targets.**
2. Click on **+ Add Devices**, search and select the required device(s) to which you need to apply the policy and click **OK**
3. Click on **Save** to apply the policies to the devices.

 Note: 
To associate the policies with a device group, select **Device Groups** from the left pane under **Policy Targets**, and follow the above instructions.

Similarly, you can associate the policy with **Users**, **User Groups**, or **Domains** from the same pane.

 

 
If you’ve already saved the policy and taken to the page which displays the policy list, 1. Select the required policy
2. Click on **Manage** > **Associate Targets**.
3. Select **Device**/ **User**/ **Device Group**/ **User Group**/ **Domain**.
4. Search and select the required policy target and click **Associate**.

What happens at the device end? 
--------------------------------

When the device comes in the range of the configured Wi-Fi network, the device connects to the configured network automatically. It gets listed among the other available networks with a tag indicating that the organization manages it. Thus, the users cannot forget the network manually, and the network configurations remain associated with the device.
[![ Wi-Fi configurations for Windows devices](https:2021/09/windows-wi-fi-policy.png "Windows Wi-Fi policy")](https:2021/09/windows-wi-fi-policy.png)

Update an existing Wi-Fi configuration
--------------------------------------

Follow the below steps to update an existing Wi-Fi configuration that has been applied to the device via a policy:

1. Create a new policy with the updated Wi-Fi configuration.
 Note:- Ensure that you also provide a new SSID for the network while updating its Wi-Fi configurations via policy.
- This newly created Wi-Fi policy (to update the Wi-Fi configurations of an existing network) should address the existing Wi-Fi network as a different network with a new SSID and other modified Wi-Fi settings.

 

3. Apply the policy to the target devices/groups.
4. Now, modify the Wi-Fi configuration on your network router (reflecting the new SSID and other Wi-Fi settings as per the newly created Wi-Fi policy).
5. (Optional) Archive the old Wi-Fi policy configured for the network.

 Exception: 
The corresponding network is disconnected and forgotten when the configured Wi-Fi policy is removed from the device. However, the **Remove Policy** action shows *In Progress* if the device does not connect to any other network. (This might happen if the Wi-Fi set up via policy was the only configured network on the device.) Note that the device needs to establish a network connection and sync with the Hexnode UEM server for the **Remove Policy** action to be successful.

 

Frequently Asked Questions (FAQs) 
----------------------------------

#### 1. Is it possible to deploy a Wi-Fi profile for a hidden SSID? 

Yes. Administrators must enable the **Hidden Network** option within the Wi-Fi policy. If this option is disabled, Windows will not send active probe requests to locate the specific network identifier, resulting in a connection failure unless the network is configured to broadcast its SSID.

#### 2. Can a device be configured to prioritize Corporate Wi-Fi over a saved Guest Wi-Fi? 

Yes. Although Windows typically determines Wi-Fi priority based on the order in which profiles are installed, administrators can ensure the corporate network takes precedence by setting the **Connection Mode** to **Auto** within the managed profile. When multiple networks are within range, Windows utilizes an internal auto-connection logic that prioritizes secure Enterprise profiles and the most recently updated managed configurations.

#### 3. Why is the option to “Forget” the managed office Wi-Fi network unavailable to users? 

Windows prevents users from manually deleting or forgetting Wi-Fi networks that are deployed as Managed Profiles. This mechanism ensures that managed devices maintain persistent and automatic connectivity to organizational infrastructure whenever the network is within range.

Troubleshooting
---------------

#### 1. The device is within range but fails to connect even though the “Connection mode” is set to “Auto”. 

**Probable Cause:**

Windows “Random Hardware Addresses” feature is enabled, and the router does not recognize the rotating MAC.

**Solution:**

Disable “Random hardware addresses” in the device’s Wi-Fi settings or ensure the router/Access Point is configured to accept randomized MACs.

#### 2. The Wi-Fi profile disappeared after a Windows Update. 

**Probable Cause:**

Major Windows updates or driver refreshes can occasionally reset the network stack or update the WLAN Miniport driver, causing deployed profiles to be “orphaned” or cleared from the active list.

**Solution:**

1. **Portal Action:** Go to the **Manage** tab, select the device, and under **Actions**, click **Scanning & Monitoring > Scan Device**.
2. **Device Action:** On the device, open the **Hexnode UEM app** and click on the **Sync** icon. This forces the OS to re-apply all associated policies and restore the missing profile.

#### 3. Error: “The policy could not be applied” (Invalid Payload). 

**Probable Cause:**

The SSID name exceeds 32 characters or contains unsupported special symbols.

**Solution:**

Ensure the SSID matches the router’s broadcast name exactly and stays within the 32-character limit.

Best Practices
--------------

#### 1. Network Profile Cleanup 

Duplicate or manual profiles can cause “conflict loops” where Windows doesn’t know whether to use the user’s old password or the organization’s new policy.

- **Remove existing profiles:** Before applying the policy, go to **Settings > Network & Internet > Wi-Fi > Manage known networks** and “Forget” any company networks previously added manually.
- **Avoid manual overrides:** Once the network is marked as “Managed,” do not attempt to change the security properties or IP settings manually in the Control Panel.

#### 2. System Synchronization and Timing 

Windows security handshakes (especially for WPA2-Enterprise) are extremely sensitive to time and state mismatches between the device and the UEM server.

- **Maintain Clock Accuracy:** Ensure “Set time automatically” is toggled **On** in Date & Time settings; a drift of just a few minutes will cause the Wi-Fi authentication to fail.
- **Force Manual Syncs:** If a policy change is made in the portal, open the Hexnode UEM app on the device and click **Sync** to pull the latest configuration immediately rather than waiting for the next scheduled cycle.

#### 3. Software and Service Readiness 

The background engines in Windows must be healthy for Hexnode to successfully “inject” the Wi-Fi settings into the operating system.

- **Keep WLAN AutoConfig Running:** Ensure the **WLAN AutoConfig** service is set to “Running” in *services.msc*. If this service is stopped, the Wi-Fi tab may disappear entirely.
- **Install Optional Driver Updates:** Check **Windows Update > Advanced Options > Optional Updates** for network driver refreshes that may improve compatibility with modern WPA3 or Enterprise encryption protocols.