Every Apple deployment I have been called into after it went wrong had the same shape underneath it. Someone treated Apple Business as a portal you visit once during setup. It is not a portal. It is the register that decides what your management platform is allowed to do, and almost every decision it holds is difficult or impossible to reverse.
There is a persistent idea that Apple Business is a formality. You sign up, you paste a token into Intune, you never look at it again, and the real work happens in the Intune admin center where the policies live. I understand where the idea comes from, because that is roughly the shape of the setup instructions, and the setup instructions are the only part most people read. It is also the single most expensive misunderstanding in Apple device management, and it produces a specific and recognisable failure: an estate where the devices are enrolled, the policies apply, and yet nothing quite works the way the design said it would. Supervision is missing on half the fleet. Apps will not install for a population that should have them. A device that came back from repair cannot be re-enrolled. Nobody can explain why, because the explanation is not in Intune.
The explanation is that Apple, not Microsoft, holds the record of what your organisation owns. Intune is a tenant of that record. It can configure a device beautifully, and it cannot assert that the device belongs to you, because that assertion is made somewhere else and was probably made at the point of purchase by a person in procurement who had never heard of any of this.
The name changed, and mostly that is all that changed
Before anything else, a correction that will save you an hour of confused searching. Apple Business Manager no longer exists as a product name. On the fourteenth of April 2026 Apple merged Apple Business Manager, Apple Business Essentials and Apple Business Connect into a single platform called Apple Business, and made it free. Apple’s own words are that the three predecessors “will no longer be available once Apple Business launches”, and the guide that replaced them now lives at a different address entirely.
That matters more than a rename usually would, for two reasons that have nothing to do with branding. The first is that every deep link into Apple’s old Apple Business Manager documentation now redirects to a single landing page headed “Apple Business Manager is now Apple Business”, rather than to the successor of the article you wanted. The heading tells you the product was renamed. It does not tell you which page you lost, so a bookmark you have relied on for three years now silently resolves to something useless. The second is that Microsoft has not finished renaming its own documentation, so Intune’s Learn pages currently disagree with each other about what Apple’s product is called and where its settings live. Two Learn pages carry the same token renewal section, one saying Apple Business and one saying Apple Business Manager. I will flag those disagreements as we hit them, because a build sheet that follows a stale navigation path is a build sheet that wastes your afternoon.
Beyond that, the rename changes very little about how any of this works. The mechanisms are the same mechanisms. Where terminology shifted I will use Apple’s current word and note the old one once. The important vocabulary changes are that an MDM server is now a device management service, a Location is now an organizational unit, and a Managed Apple ID is now a Managed Apple Account. Apple School Manager kept the older vocabulary, including MDM servers, and is very much alive, so a search that lands you on School Manager documentation is showing you accurate information about a different product.
Three registers, and what each one governs
What Apple Business actually holds is three separate registers, and it is worth naming them separately because they fail separately and they are administered by different people in most organisations.
The first is ownership. Apple Business is the authoritative statement that a given serial number belongs to your organisation. That statement is not made by enrolling the device, and it cannot be made retroactively by any amount of configuration. It is made at the point of purchase, by the reseller or carrier submitting the order against your organisation identifier, or afterwards by an administrator manually adding the device with Apple Configurator. Everything that distinguishes a corporate Apple device from a personal one descends from that record: supervision, the enrolment prompt the device shows on first power-on, a management profile the user cannot remove, and Activation Lock bypass codes that let you recover a device when an employee leaves without unlocking it. None of that is available to a device Apple does not believe you own.
The two routes are not quite equivalent, and the difference matters later. A device that entered through the purchase channel is yours from the moment it appears. A device added by hand with Apple Configurator behaves like any other device in the register, with mandatory supervision and enrolment, but Apple gives its user a thirty day provisional period in which they can release it from your organisation, your supervision and your management service. For thirty days, that management profile is removable after all. [AB 6.2] deals with what that means in practice.
The second is identity. Apple Business holds your organisation’s people as Managed Apple Accounts, which are accounts your organisation owns rather than accounts your employees own. This is the register that decides whether a user signing into an iPhone is signing in as themselves or as a representative of you, and it is the one that connects to Microsoft Entra ID. It also holds your verified domains, and with them the power to reach into personal Apple accounts that were created on your domain name and take them over. That capability is called Domain Capture. It cannot be undone, it starts a thirty day clock that cannot be extended, and Apple emails every affected person without telling you in advance who they are. It gets its own build sheet in [AB 4.1] rather than a paragraph, because the hard part is not the button, it is finding the people before you press it.
The third is entitlement. Volume purchased apps are licensed to your organisation inside Apple Business, and the token that lets a management platform assign those licences is issued there. Intune does not own a single app licence. It holds a token that lets it ask Apple to assign licences on its behalf, and Microsoft says so plainly in its own documentation: Intune does not install volume purchased apps, it tells Apple which licences to assign to which devices, and the installation happens between Apple and the device with Intune watching.
Intune configures. Apple Business decides what Intune is allowed to configure, and on whose hardware.
Hold those three apart in your head and a lot of otherwise baffling behaviour becomes predictable. An app that will not install on a personally enrolled iPhone is an entitlement problem, not a policy problem. A Mac that enrols but will not accept a configuration you know is correct is usually an ownership problem wearing a policy costume. A user whose Apple account keeps signing itself out is an identity problem, and the fix is in a console Microsoft does not operate.
The sentence that makes zero touch possible
Apple states the entire mechanism of automated enrolment in one sentence, and it is worth reading slowly because everything in this series depends on it. You assign a device to a device management service so that Setup Assistant displays the pane to enrol the device in that service.
That is the whole trick. A new iPhone powers on, contacts Apple during activation, asks whether anyone has a claim on it, and Apple answers with the name of your management platform. The device then enrols itself before a human has touched a single setting. It is genuinely elegant, and it works only because the claim was registered in advance, on hardware Apple already knew about, against an organisation Apple had already verified. Take away any one of those and the pane never appears, the device sets itself up as a personal device, and your zero touch deployment becomes a person in the office with a box of iPhones and an afternoon to lose.
This is also why the ordering discipline in this series is so heavy. A device that boots before it has been assigned an enrolment policy does not get a second chance without a factory reset. An enrolment policy that is edited after devices are assigned does not apply the edit until those devices are reset, with the single exception of the device name template, which takes effect at the next check-in. A device released from Apple Business can be added back, but Apple states that managing its Activation Lock through Apple Business is not possible after a release. Apple Business is full of doors that only open one way, and most of them are not labelled.
Apple now ships its own management service, and it does not change the argument
One genuinely new thing arrived with the 2026 merge, and it deserves naming here so that nobody discovers it halfway through the series and wonders why I hid it. Apple Business now includes a built in device management service at no cost. It is the engine that used to be sold as Apple Business Essentials, and Apple’s announcement describes it as offering “built-in mobile device management (MDM), facilitating a comprehensive view of an organization’s Apple devices, settings, and more from a single interface”. For an Apple only business with no Microsoft estate, that is a real product and a genuine alternative to paying for anything.
It does not compete with Intune in the estates this series is written for, and Apple did not build it to. Apple’s documentation is explicit that an organisation can connect more than one device management service and assign devices between them, which means the built in service sits alongside Intune rather than in place of it. What it cannot do is the thing an Intune estate is built around. Apple’s platform list is iOS, iPadOS, macOS, tvOS, visionOS and watchOS, so it has no reach into Windows or Android at all, and that much is documented. The rest is my reading rather than anybody’s published statement: neither Apple nor Microsoft documents any compliance signal from Apple’s service into Entra ID, and without one it cannot participate in Conditional Access. Wherever your access control depends on knowing a device is healthy before it sees your data, I do not believe the built in service is a substitute at any size. I will make that case properly in the capstone, with the honest list of who should use it and what I could not verify.
There is one trap worth carrying from here, because it fires long before the capstone. On an organisation that moved across from Apple Business Manager or Apple Business Essentials, turning on built in device management when the primary organisational unit’s content token has never carried an app assignment causes that unit to become reserved. Apple’s words are that the token then does not appear, so you cannot link an external device management service to distribute apps from it. That specific token does not come back. Apple does document a way onward, which is to create an additional organisational unit and move licences into it, so this is recoverable rather than terminal. It is still an afternoon you did not need to spend, and there is no confirmation dialogue warning you before it happens. Do not enable the built in service to have a look at it.
What this series does
The worked estate throughout is CatSnackJack, the same fictional company the Active Directory series decommissioned a domain for: around a hundred and forty people, Microsoft 365 Business Premium, Intune already running for Windows, and a growing pile of iPhones that were bought through a carrier by whoever needed one. That is a realistic starting point and it is deliberately not a clean one.
From here the series builds an Apple Business organisation and verifies it, works out who inside it should be able to do what, then takes on identity: your domains, the personal Apple accounts already sitting on them, and only then federation with Microsoft Entra ID so that people sign into Apple devices with the credential they already have. That order is Apple’s, not mine. Apple states that if your goal is federated authentication you need to lock and capture the domain first, which surprises people who expect capture to be optional. After identity, the series gets devices into the register from whichever channel you actually buy through, and links the whole thing to Intune. Then it opens the doors a device can come in through. Apple groups enrolment into three methods, being User Enrollment, Device Enrollment and Automated Device Enrollment, but from an Intune administrator’s seat there are four practical routes with genuinely different consequences: Automated Device Enrollment for hardware straight out of the box, web based device enrollment and account-driven user enrollment for devices already in someone’s hands, and Apple Configurator for the ones you can physically reach. Two of those four need no wipe. After that the series moves an existing fleet off another management platform, and finishes with the parts nobody writes about: app licensing, the seam between what Apple configures and what Intune configures, and what happens to a device at the end of its life.
Where this series meets ground the Intune guide already covers, it points rather than repeats. Supervision doctrine lives in [9.4.2] iOS Supervised Mode, Mac management lives across Phase 11, and app packaging lives in Phase 7. What is new here is everything on the Apple side of the seam, and the seam itself, which is where most of the failures actually happen.
The next article is the one that gets you an organisation, and it starts by dismantling the most repeated piece of misinformation in this whole subject: that you need a D-U-N-S number.
Apple Business
Next: [AB 2] Getting an Organization: Two Methods, and the D-U-N-S You No Longer Need ›




