MAC Address Randomization: device-specific limitations and workarounds
Android
When MAC address randomization is configured in a Blueprint, Samsung devices and Galaxy Watches running WearOS do not apply the setting — and any manual changes made directly on the device are silently overwritten the next time Esper pushes a Wi-Fi profile update.
Why this happens
Esper's MAC address randomization control relies on Android APIs that Samsung and WearOS devices do not expose to device management software. Because the setting cannot be enforced at the OS level on these devices, the Esper Agent has no mechanism to apply or preserve it. When a Wi-Fi profile is pushed or updated, the profile is written fresh, discarding any randomization state set manually on the device.
Supported devices
MAC address randomization is supported on Lenovo devices running Android 12 or later. It is not supported on:
- Samsung Android devices (any model)
- Samsung Galaxy Watches and other WearOS devices
Check whether the setting applies to your device
- Open the Esper Console and go to Blueprints.
- Open the blueprint applied to your device and navigate to Connectivity.
- Locate the MAC Address Randomization toggle. If the toggle is visible but your device is a Samsung or WearOS model, the toggle will have no effect — the setting will not persist on the device.
Workarounds for Samsung and WearOS devices
Because MAC address randomization cannot be disabled on these devices through Esper, use one of the following network-side alternatives:
- Remove MAC address filtering for the affected SSID. Replace it with an access control method that does not depend on a fixed hardware address, such as certificate-based (802.1X) authentication or a VPN.
- Create a dedicated SSID for WearOS devices. Segment these devices onto a separate network that does not enforce MAC address filtering, keeping them isolated from infrastructure that requires a stable MAC.
- Accept randomized MAC addresses. If neither option above is feasible, allow these devices to operate with randomization enabled and update your network allowlist accordingly.
Do not attempt manual changes on the device
If MAC address randomization is manually disabled directly on a Samsung or WearOS device, the change will be overwritten the next time Esper applies a Wi-Fi profile update. This occurs on every UPDATE_WIFI_AP and ADD_WIFI_AP command. Manual changes on the device are not a reliable workaround.
If the setting is not applying on a Lenovo device
If your device is a supported Lenovo model running Android 12 or later and MAC address randomization from a blueprint is still not applying, check the following before contacting support:
- Go to Devices & Groups → [Device Name] → Device Info and confirm the device is running Android 12 or later.
- Go to Devices & Groups → [Device Name] → Apps and confirm the Esper Agent is on the latest available version. If not, go to Esper Software Updates to push the latest agent build.
- Go to Devices & Groups → [Device Name] → Activity Feed and check for any errors related to Wi-Fi profile commands.
If this doesn't resolve it
If the setting is confirmed unsupported on your device model, or if a supported Lenovo device is still not applying randomization correctly, contact Esper Support. Include the following when you reach out:
- Device manufacturer and model number
- Android OS version
- Esper Agent version
- A description of the observed behavior and the expected behavior
- Any relevant entries from the Activity Feed
Still need help?
If MAC address randomization is causing connectivity or management issues on your devices, submit a support ticket and include your device model, Android version, and specific symptoms you're experiencing.
Please sign in to leave a comment.
Comments
0 comments