Mobile Device Management Solution Hexnode MDM Frequently Asked Questions www.hexnode.com
Frequently Asked Questions How is Hexnode MDM license calculated?...4 Which ports do I need to open for Hexnode MDM?...4 Does Hexnode MDM need an internet connection to work?...4 What are the requirements to manage mobile devices with Hexnode MDM?...4 How long does it take for the polices to be activated on the devices?...5 Does using Hexnode MDM affect the device's manufacturer warranty?...5 How do I know if a device is unprotected?...5 What do I do if a device ceases to respond to the actions initiated?...5 How much user intervention is required while managing the devices?...5 How do I configure the APNs settings in Hexnode MDM?...5 How do I renew the APNs certificate?...6 How do I configure the email server settings?...6 How do I configure my Active Directory in Hexnode MDM?...7 How do I configure the NAT settings for Hexnode MDM...7 How do I enroll mobile devices in Hexnode MDM?...7 Can I cancel an already sent enrollment request?...8 What are the steps an end user should follow while enrolling their device?...8 Do I have to re-enroll a device after being wiped?...8 Do I have to re-enroll a corporate-owned device after it changes hands?...8 What does enrolling do to my mobile device?...9
How do I disenroll a device?...9 What can I do if a user forgets their password?...9 What can I do if my mobile device is stolen?...9 How do I lock a device remotely?...10 How do I wipe a device remotely?...10 How do I configure Wi-Fi settings on a user device?...10 How do I configure email on a user device?...10 How do I disable camera on a user device?...11 How do I disable icloud backup?...11 How do I disable itunes store on a user device?...11 How do I install specific apps on the user devices?...11 How do I blacklist an app on the user device?...12 Can I push enterprise apps to the user devices?...12 How secure is Hexnode MDM architecture?...12 How is the Hexnode MDM process flow supposed to work?...12 How can we manage corporate data in personal devices?...13 How can we manage BYOD?...13
How is Hexnode MDM license calculated? Hexnode MDM license is based on the number of devices. If you have a license for say, 100 devices, you can enroll up to 100 devices. You can view your current license in the Hexnode MDM admin panel. If you have purchased a new license and have the license key with you, you can upload it to renew your license. Which ports do I need to open for Hexnode MDM? Hexnode MDM needs the following ports to be open for communication. Port 80 :The default application port used during the installation of Hexnode MDM. Port 443 :Used for secured and encrypted connection between mobile devices and Hexnode MDM. Port 2195 (outbound): This port must be open for the Hexnode MDM server to communicate with APNs (Host Address is gateway.push.apple.com). Port 5223(outbound): If the mobile devices are connected to the internet through a Wi-Fi, this port should be open. Does Hexnode MDM need an internet connection to work? Yes, you need to have an internet connection for both Hexnode MDM and the managed mobile devices. What are the requirements to manage mobile devices with Hexnode MDM? Before you can start managing the devices, you need to configure the following settings in the Hexnode MDM admin panel. 1. APNs settings 2. Proxy settings 3. Email Server settings 4. AD import/csv import of users How long does it take for the polices to be activated on the devices? If the device is connected to the internet, the policies get activated instantly. If there is no
connectivity, the policies will be activated on the device the next time an internet connection is established. Does using Hexnode MDM affect the device's manufacturer warranty? No, Using Hexnode MDM does not affect the manufacturer's warranty in any way. How do I know if a device is unprotected? Hexnode MDM alerts you whenever a device goes out of compliance. You can view the compliance status from the dashboard. Detailed information on compliance are displayed under the device info for each device. Various compliance reports are also available in the reports category. What do I do if a device ceases to respond to the actions initiated? Check, the internet connection on the device. If a device seems to not respond, it means the commands initiated from Hexnode MDM cannot reach the device. It's most likely due to the device being disconnected from the internet. However, the remote actions you have initiated will take effect on the device when it gets connected to the internet again. How much user intervention is required while managing the devices? User intervention is required only during enrollment. Once a device is enrolled, you can mange it with zero effort on part of the users. How do I configure the APNs settings in Hexnode MDM? You can follow the steps below to configure APNs in Hexnode MDM. Step 1: Create a CSR (Certificate Signing Request) i. Go to Admin tab, click on APNs settings
ii. Click on configure APNS certificate iii. Click on download CSR to download the self-signed CSR Step 2: Download APNs certificate. i. Go to the Apple Push Certificates Portal website. Log in using your company apple ID and password. ii. Upload the CSR request previously generated. Iii. Download the APNs certificate. Step 3. Upload APNs certificate. i. Upload the APNs certificate back in to Hexnode MDM and you're done. How do I renew the APNs certificate? Your APNs certificate has a validity of one year after which you'll have to renew it. For renewing the certificate, Go to admin > APNs settings. Click on renew certificate and follow the same procedure for configuring APNs settings. How do I configure the email server settings? Hexnode MDM lets you send email notifications to the users. You can configure Hexnode MDM to send notifications through any service you use for email. You will need to configure the relevant email server settings within Hexnode MDM. Choose Admin > Email settings Specify the following, Server name: Outgoing email server name or IP address of the email service provider Port number: Communication port number of the email server Sender's email address: The email address used for sending emails Enable TLS: Select this option, if Transport Layer Security is enabled in the mail server. Enable SSL: Check this option, if SSL(Secure Socket layer) is enabled. Enable Authentication: If outgoing email authentication is required in the email server, choose this option and provide the credentials required for authenticating the outgoing emails. Once you enter all the settings, you can send a test mail to verify. Click save to use the current settings.
How do I configure my Active Directory in Hexnode MDM? You can configure your Active Directory to bring your users, groups and OUs as such into Hexnode MDM. For configuration, Select Admin > AD settings If you have already configured one, it will be displayed there. You can click on it to edit settings. To add a new Active directory, click on the empty slot with the + symbol. Specify the following: Domain Name: Your Domain Name AD Server: AD server Port: Port No. Domain\User Name: Password: Selected OUs: By default all the OUs in the domain will be selected. You can click on change to choose the specific OUs you want. Change Allow SelfEnroll: By enabling this, you can let the users in this particular domain to enroll directly from the portal without sending enrollment requests. Schedule Sync: You can choose here, how often you want the AD to be synced with Hexnode MDM. How do I configure the NAT settings for Hexnode MDM Mobile Devices should be able to communicate with Hexnode MDM even when outside the office Wi-Fi network. You can configure your NAT settings within Hexnode MDM to make it possible. To configure, Select Admin > NAT settings Specify the NAT server, HTTP and HTTPS ports. If you want to connect server from an outside firewall, you can specify an alternate server configuration as well. How do I enroll mobile devices in Hexnode MDM? Enrolling mobile devices is easy. You can start by sending out enrollment requests to a domain, OU, user group or individual users. If you enable self enrollment option in the AD settings, you can skip ahead of requesting and users can directly access the Hexnode MDM enrollment portal to register
their devices. At the enrollment portal, users will be validated against their AD credentials or an OTP depending on the type of enrollment. After validation, Users just need to tap the Enroll button and follow these steps 1. When you tap enroll, an MDM configuration profile will be downloaded. You will be prompted to install it on your device. 2. Tap install and the profile installation will begin. 3. Once the installation is successful, you'll receive this message 'Congratulations, you are now enrolled with Hexnode MDM.' Can I cancel an already sent enrollment request? Yes, You can cancel the request sent for enrollment under enrollment tab. Go to enrollment list view > select the request(s) > click on Cancel Pending requests. Once cancelled, the enrollment link will no longer be active. What are the steps an end user should follow while enrolling their device? The administrator sends an email containing the enrollment link to the user. User needs to 1. Tap on the link and type in the username and one time passcode provided in the email. 2. Tap on the install button to install the Hexnode MDM profile Once the profile is successfully installed, the enrollment process is complete. Do I have to re-enroll a device after being wiped? On wiping a device, the entire data on the device will be deleted and the settings restored to factory defaults. After wiping, the device should be re-enrolled to be managed with Hexnode MDM. Do I have to re-enroll a corporate-owned device after it changes hands? No, you need no re-enroll the device. You can change the owner from within Hexnode MDM. Choose Home > Management > Devices
Select the device. Click on manage and select Change user. Choose the user domain and select the specific user and click on assign. Now the device will be assigned to the new user. All the policies relevant to the new user will be automatically applied on the device. What does enrolling do to my mobile device? Enrolling is the process of registering a mobile device with Hexnode MDM. It is the first step towards managing and securing the device. Once a device is enrolled, Hexnode MDM will be able to securely communicate with the device and activate the configurations and restrictions you have set for the device. How do I disenroll a device? To disenroll a device from Hexnode MDM, Choose Home > Management > Devices From the device list, select the device you want to disenroll. Click on Manage and select Disenroll Device. The selected device will be disenrolled. Disenrolling the device will, will remove all the configurations and settings you have set up with Hexnode MDM. The device needs to be re-enrolled with Hexnode MDM to be managed What can I do if a user forgets their password? You can reset the device password from Hexnode MDM. Choose Home > Management > Devices Select the device. Click on Manage and Select Clear Passcode. The device Passcode will be reset. What can I do if my mobile device is stolen? When a mobile device is stolen, the administrator can remotely wipe the device from Hexnode MDM. To initiate device wipe,
Choose Home > Management > Devices From the device list, select the stolen device. Click on Manage and select Wipe Device. The selected device will be wiped. This will delete all of the device data and will restore the device settings to factory defaults, so you can be rest assured, the data is safe. How do I lock a device remotely? You can remotely lock a device using Hexnode MDM. Choose Home > Management > Devices Select the device. Click on manage and Select Lock Device. This will lock the device. How do I wipe a device remotely? You can remotely wipe a device using Hexnode MDM. Choose Home > Management > Devices Select the device. Click on manage and Select Wipe Device. This will wipe the device. How do I configure Wi-Fi settings on a user device? Select Home > Polices Select New Policy. Click on Network. Choose Wi-Fi and click on the Configure button. Now you can set up your Wi-Fi settings. You need to specify your SSID, Authentication type and password. Check Hidden Network if you do not want the SSID to be transmitted. Enable Auto join if you want the devices to automatically connect to the network, if within range. You can configure your proxy settings as well. Once you are done, click Save. Now Click on Policy Targets and select the desired device. Wi-Fi settings will be instantly set up on the device. How do I configure email on a user device? Select Home > Polices Select New Policy. Click on Network. Choose Email and click on the Configure button. Now you can set up your Email settings. Give an account description and Display name and specify the email address. Choose the account
type. Check Allow Move if you want to able to mobile mails between different inboxes. Specify the incoming and outgoing mail settings and key in the credentials. Check 'Allow Recent Address Syncing' if you want the recent email addresses to be synced across the devices. Check 'Use only in mail' if you want to disable sending mails using other apps like Safari and photos. Once you are done, click Save. Now Click on Policy Targets and select the desired device. Email settings will be instantly set up on the device. How do I disable camera on a user device? Select Home > Polices Select New Policy. Click on Restriction. Uncheck 'Allow use of camera'. When you disable camera Facetime app won't work either. Click Save. Now Click on Policy Targets and select the desired device. Camera app will instantly disappear from the device. How do I disable icloud backup? Select Home > Polices Select New Policy. Click on Restriction. Under icloud, Uncheck 'Allow backup'. Click Save. Now Click on Policy Targets and select the desired device. Users won't be able to backup data in icloud. How do I disable itunes store on a user device? Select Home > Polices Select New Policy. Click on Restrictions. Uncheck 'Allow use of itunes store'. Click Save. Now Click on Policy Targets and select the desired device. itunes Store app will be instantly disabled on the device. How do I install specific apps on the user devices? Choose Home > Management > Devices Select the device. Click on Manage and select Install Application. Under local apps, you can see the apps in your inventory. If you want to install an application not on the list, click on Public Store and
search for the particular app. Once you have selected the app, click done and the selected app will be installed on the user device. How do I blacklist an app on the user device? Select Home > Polices Select New Policy. Click on App Management. Choose Black/White list. Check Blacklist in type. Select Add > Add app. Under local apps, you can see the apps in your inventory. If you want to blacklist an application not on the list, click on Public Store and search for the particular app. Once you have selected the required apps. Click Save. Now Click on Policy Targets and select the desired device. The desired apps will be blacklisted for the device. Can I push enterprise apps to the user devices? Yes, with Hexnode MDM, you can push your enterprise apps to the user devices. Select Admin > App settings > Apps Click on Add apps and choose Enterprise app. You can upload the ipa file for your app package or specify the manifest url. Select the category for your app and provide a description. Check Remove with MDM if you want the app to be uninstalled on removing the MDM profile. Check prevent backup to disable the enterprise app data from getting synced with the users personal itunes account. Once you have selected the app click on add. The enterprse app will be added to your app inventory. Now for installing this app on a user device. Choose Home > Management > Devices Select the device. Click on Manage and select Install Application. Under local apps, you can see the enterprise app you have uploaded. Once you select the app, click done and the app will be installed on the user device. How secure is Hexnode MDM architecture? Hexnode MDM is built on top of a highly secure architecture and employs the Apple Push Notification serveice (APNs) and the Google Cloud Messaging Service for securing communication with the user devices. See Hexnode MDM architecture
How is the Hexnode MDM process flow supposed to work? Hexnode MDM process flow is simple and easy to understand. Learn all about Hexnode MDM's working and process flow in here. Hexnode MDM features overview How can we manage corporate data in personal devices? When you manage devices with Hexnode MDM, the corporate settings like Email, Wi-Fi, Calendar, Enterprise apps all are handled via policy in a configuration profile installed on the user devices. When a user leaves the company, you do not have to factory reset the device, you can just disenroll the device from Hexnode MDM. Upon disenrollment, this configuration profile will be uninstalled from the device, removing all the associated settings with it, thereby leaving no trace of corporate data. Disenrollment is practically a corporate data wipe, it does not interfere with the user's personal data or settings on the device. How can we manage BYOD? Hexnode MDM lets you handle BYOD devices separately, right from enrollment. While sending out the enrollment request to users, you can pre-select whether a device is user owned or corporate owned. You can also let the user decide whether it is BYOD or Corporate owned. To enroll a BYOD device, Select Home > Enrollment Click on New Enrollment. Once you choose the domain and select the user, under Ownership, select Personal and click send. The selected device will be enrolled as a BYOD device. Now you can create a group with all the user owned devices and assign them a BYOD policy. You can also create a dynamic group with ownership criteria as BYOD, so that every new BYOD device enrolled will be added to that group. To create a dynamic BYOD group Select Home > Management > Device groups Click on New group. Give a group name and description. Check Dynamic group.
In conditions, check All of the below conditions and choose Device info Ownership Is Personal. And Save group. Now all the devices enrolled as BYOD will be automatically added to this group. Now assign the required BYOD policy to this group and you're done. Email : mdm-support@hexnode.com US :+1-510-545-9700 India :+91-484-297-4545