[AB 2.1] Build Sheet: Sign-Up, Verification, and the Organization Profile

By the end of this you have a verified Apple Business organization, two Organization Administrators, a verified domain, your purchase history visible, and your Organization ID recorded, with every irreversible step gated by a check that runs before it rather than after.


By the end of this article you have an Apple Business organization that Apple has verified, a second Organization Administrator so a terms update cannot lock you out, a verified domain, your Apple purchase history visible in the register, and your Organization ID written down where procurement can find it. Nothing is connected to Intune yet, and that is deliberate.

The worked estate is CatSnackJack, a hundred and forty seat business on Microsoft 365 Business Premium with Intune already managing Windows. It owns the domain catsnackjack.com, it is not incorporated in a way that has ever produced a D-U-N-S number, and its iPhones were bought piecemeal through a carrier by whoever needed one. Where your situation differs, the step says so.

Prerequisites. A work email address that has never been used as an Apple Account and is not associated with an App Store or iCloud account. Write access to your public DNS zone, or a person who has it and will answer within a fortnight. One official document proving the organisation exists, from Apple’s accepted list. The legal name and mailing address exactly as they appear on that document. Your Apple Customer Number if you have ever bought from Apple directly, obtainable from purchasing or finance, since Apple publishes no self-service lookup. A supported browser, which as of writing means Safari or Chrome on iOS or iPadOS 16.6 and later, Safari 16.6 or Chrome 138 or Edge 138 or Firefox 140 on macOS 11 and later, or Chrome, Edge or Firefox at those versions on Windows.

Two honest exceptions before you start. First, there is no scriptable path through sign-up. Apple Business has a full REST API, covered in [AB 16], but creating an API account requires the Organization Administrator role in an organisation that already exists, so it cannot bootstrap the thing this sheet builds. The portal is the only route and I will not invent a command to pretend otherwise. Second, the genuinely scriptable part of this build is the DNS verification, and the commands below are there because they are the difference between a fourteen day clock you complete and one you restart.

Naming convention. Adopt one before step 1, because two of these names are difficult to change afterwards. Organization Administrator accounts take the form ab-admin-firstname.lastname@yourdomain, which makes them obviously administrative in a mailbox list and obviously not a personal Apple account. Organizational units take the form of the business unit they represent with no punctuation, so Head Office and Field Service rather than abbreviations, because these names appear in app licensing screens that other people will read. The initial organizational unit is created for you and named after your organisation, and it is the one unit you cannot rename, so do not plan around renaming it.


Step 1. Gate the account you are about to sign up with

This check goes first because the address you sign up with becomes your first Organization Administrator, and Apple rejects an address that is already an Apple Account, is associated with an App Store or iCloud account, or belongs to a domain another Apple School Manager or Apple Business organisation has verified. Discovering any of that after you have filled in the organisation details means starting over.

The reliable way to pass this gate is to sidestep it. Create a brand new mailbox for the purpose rather than reusing a person’s address. A mailbox created this morning cannot already be an Apple Account, which turns an unknown into a certainty and costs you two minutes. For CatSnackJack the address is [email protected], created for this and used for nothing else.

If you are constrained to an existing address, you can probe it by starting a password reset for it at Apple’s account recovery page and reading how far the flow gets before you abandon it. Treat that as an indication rather than a test: account recovery flows are commonly designed not to disclose whether an address is registered, and I have not confirmed what Apple’s currently reveals. A negative result there does not prove the address is free, which is the whole reason the new mailbox is the recommended path.

Failure mode to watch for either way: an address somebody in the business used years ago for a shared iPad and forgot about. This is common, it is invisible from your mail system, and it produces a rejection at sign-up that reads like a validation bug rather than like an explanation.


Step 2. Create the organization

Go to business.apple.com and choose to sign up. Apple asks for the organisation, then for you, then verifies both your email address and your phone number with one time codes. The fields that matter, and what to put in them:

SettingValueWhy
Organization nameYour legal entity name as it appears on the verification documentApple states this name may change when you verify. Matching the document up front avoids a mismatch that stalls review.
Website URLYour public siteOptional, and Apple says providing it can expedite verification. There is no reason to leave it blank.
Third-party partner or agency checkboxLeave uncheckedThis is for data providers managing brand presence on behalf of other companies. Checking it puts you on a different verification path and removes the App Store Connect option.
First and last nameA real human nameApple returns role names such as IT Coordinator for correction, which costs you a round trip.
Phone numberA number you can receive an SMS or call on right nowThe one time code arrives during the flow, not afterwards.

Accept the Apple Business terms and conditions when prompted. The employee count and interest questionnaire that follows can be skipped and has no effect on verification.

Expected result: you land in Apple Business as an Organization Administrator, with an unverified organisation and a sixty day clock now running.


Step 3. Choose your verification methods before you touch the portal

Verification needs two methods. The first is one of three options and the second is an uploaded document. Decide both now, on paper, because the review takes up to five business days and a rejected submission spends a week of your sixty days.

SettingValueWhy
First methodBusiness IDFastest if you already hold an EIN or a D-U-N-S number. Do not obtain one solely for this; the other two options exist.
First methodDomain ValidationThe right choice for most organisations that own a domain and have DNS access. Costs nothing and depends on nobody outside IT.
First methodApp Store ConnectOnly if your organisation publishes an app. Not offered to third-party partners or agencies.
Second methodBusiness license, sales tax permit, food or health or alcohol permit, lease or property agreement, utility bill, or otherApple’s accepted list. Pick the one whose printed legal name and address match what you typed in step 2 exactly.

Worked example. CatSnackJack has no D-U-N-S number and does not publish an app, so the first method is Domain Validation against catsnackjack.com. For the second method finance produces a commercial lease agreement for the office, on which the tenant is named exactly as the organisation was typed in step 2. That pairing satisfies both methods with no registry identifier anywhere in the process, and it is the pairing most small organisations should use.

File provenance. Exactly one file moves between people in this build: the verification document. It comes from whoever holds the organisation’s records, usually finance or the office manager, and it is consumed once by the browser upload in step 5. It does not need to live anywhere afterwards. Keep it out of a shared drive if it carries an address that is somebody’s home.

A note on Apple contradicting itself here. The sign-up page names D-U-N-S and EIN as the Business ID options and links to a reference table of accepted Business ID types. That table contains no mention of D-U-N-S at all and defines a Business ID purely in tax terms, listing a single federal taxpayer identification entry for the United States. If you are choosing the Business ID path, read the actual picker in the portal rather than either page, because the label Apple prints in the interface is the only one that governs what it accepts.


Step 4. Add and verify the domain, with the gate in front of the clock

Adding a domain starts a fourteen calendar day window, and Apple’s wording is that if you do not complete verification inside it you need to start over. So the checks go first.

Verification gate, before you add the domain. Confirm you can write a TXT record to the zone today, not in principle. In your DNS provider’s zone editor, add a TXT record on the root of the domain with the value vcio-dns-writecheck and save it. Then read it back from somewhere outside your own network, using any public DNS lookup site, querying for TXT records on your domain.

Expected result: the throwaway string appears in the answer within your zone’s time to live. That is the pass condition and it proves three separate things at once. You have write access. The change actually publishes. And the zone you are editing is the zone the internet resolves, which is the one that matters. Remove the throwaway record before continuing.

Failure mode: the record never appears, because you edited a zone that is no longer authoritative. This happens constantly at organisations that changed DNS provider and left the old zone sitting in the old provider’s console, where it still looks perfectly convincing. Reading back from outside is what catches it; reading back from the provider’s own interface will show you the record whether or not the world can see it.

If you have a terminal to hand, the same check is two commands, and querying more than one resolver is the part that catches the stale zone.

dig +short TXT catsnackjack.com @1.1.1.1
dig +short TXT catsnackjack.com @8.8.8.8

Now add the domain in Apple Business under Settings, in the Domains area, and start verification. Apple issues a TXT value in the shape apple-domain-verification= followed by a random string.

Do not retype that value and do not copy it from this article. Apple generates it per domain and it appears nowhere except your own portal. Copy it from the screen into the zone, then read the published record back from outside and compare it against the portal rather than against your memory of it. Character for character: a truncated paste is the most common reason a verification that should work does not, and the error Apple returns does not tell you that is what happened.

Only when the published value matches the portal, from a lookup made outside your network, complete the verification in Apple Business.

One condition Apple imposes that no lookup can test for you: only domains that have not already been verified by another organisation can be added. If your domain was verified years ago by a School Manager organisation created for a pilot nobody remembers, you will hit a Domain already claimed alert after verification, and the route through it is the Contact Apple Support control on that alert rather than anything in DNS. Apple will investigate ownership and notify you, and where more than one organisation has a valid claim, no single organisation can verify it.

One reassurance, because anybody who did this in the old Apple Business Manager will be tense at this step. Verifying a domain does not email your users. The only notification is to you, confirming that the domain you selected is now being verified. In the pre-2024 product the user notifications were bolted onto verifying and federating a domain, which is why administrators of that era remember the emails going out during domain onboarding. They are now a separate, deliberate, clearly labelled step called Domain Capture, and nothing in this build sheet triggers it. That step, and how to find the affected people before you take it, is [AB 4.1].


Step 5. Submit for review

In Settings, under Organization, choose to verify. Supply the first method you decided in step 3, upload the document as the second, and send it for review.

Verification gate, before you submit. Read the legal name on the uploaded document and the organisation name in Apple Business side by side and confirm they match, including punctuation and any suffix such as Limited or LLC. Confirm the address on the document matches the address you entered. This is a thirty second check that prevents the single most common rejection, and a rejection costs you days of a sixty day window rather than minutes.

Expected result: the organisation moves to a pending review state and Apple’s stated turnaround is up to five business days, longer during high volume. Apple’s documentation retains one sentence about being able to reach a contact you provided, inherited from the older process, and there is no contact field in the current flow. Watch the administrator mailbox anyway and keep it out of aggressive spam filtering, because that is where any request for a different document will land.

Failure mode with a hard consequence: if the organisation is not approved before the sixty day window closes, Apple deletes the organisation, its data, and its Managed Apple Accounts. There is no recovery step for this because there is nothing left to recover. Put the sixty day date in a calendar the day you sign up.


Step 6. Create the second Organization Administrator

Do this the moment verification completes and before anything else. Apple allows ten Organization Administrators in total, the founder plus nine, and the reason to hold more than one is not disaster recovery. It is that when Apple updates its terms, an Organization Administrator must sign in and accept them, and until somebody does, most of Apple Business is unavailable.

Create the user in the People area, then assign the Organization Administrator role. Use the naming convention: [email protected]. Assign it to a second human who is not the first human and does not share their holiday calendar.

Expected result: two accounts hold Organization Administrator. Apple’s roles page states there can be only ten total users with that role, so a large organisation should treat these ten as a scarce resource and give everyone else a narrower role, which is the subject of [AB 3].


Step 7. Record the Organization ID and enter your Apple Customer Number

Your Organization ID is your unique identifier in Apple Business and it is the value you hand to a reseller or carrier so they can submit your purchases against your organisation. Read it from Settings, under Organization, in the details area, where Apple provides it to copy.

This is a derived value and it is different for every organisation. Do not retype one from any article including this one. Copy it from your own portal, put it in whatever your procurement team actually reads, and expect to be asked for it by every supplier you deal with.

If your organisation has ever purchased from Apple directly, add the Apple Customer Number now, in the Devices area under Inventory. One rule catches people every time and Apple states it in more than one place: omit any leading zeros. A customer number of 0004821766 is entered as 4821766.

Expected result: devices your organisation bought directly from Apple after the first of March 2011 appear in the inventory. Failure mode: nothing appears, which usually means the legal name and mailing address on the Apple Customer Number do not match those on the Apple Business organisation, a condition Apple states as a requirement and does not explain when it fails.

CatSnackJack bought its Macs through a reseller and its iPhones through a carrier, so nothing appears here at all. That is the expected result for most organisations of this size, and the fix is supplier linking rather than anything on this page.


Step 8. The end-to-end test

A build sheet that ends with the last configuration step has not proved anything. This one proves three things with a single action.

Open a private browser window on a machine that has never signed into Apple Business, and sign in as the second Organization Administrator created in step 6. Navigate to the organisation details.

Expected output: the sign-in succeeds, the organisation shows as verified rather than pending, and the Organization ID is visible and identical to the one recorded in step 7. That single observation confirms that verification actually completed, that the second administrator’s role assignment took effect, and that you have a working second path into the organisation if the first administrator is unavailable when Apple next changes its terms.

Pick the private window deliberately. Signing in from the same browser session as the first administrator proves nothing, because a cached session will happily show you the organisation regardless of whether the second account works.


One thing not to do

Apple Business now includes a free built in device management service and there is a control that turns it on. Do not turn it on to see what it does.

On an organisation that moved across from Apple Business Manager or Apple Business Essentials, enabling it when the primary organisational unit’s content token has never carried an app assignment causes that unit to become reserved. Apple’s own words are that the token then does not appear, so you cannot link to a third-party device management service to distribute apps. That token does not come back. There is no confirmation dialogue warning you, because from Apple’s point of view you asked for its management service and it gave you one.

It is recoverable, and it is worth knowing the way out before you need it rather than after. Apple documents that an external service can use content tokens belonging to organisational units other than the primary one, so the route back is to create an additional organisational unit, transfer the licences you want into it, and use that unit’s token with Intune. You lose the primary unit’s token and a couple of hours, not your app estate.

The ordering that avoids the whole detour is covered properly in [AB 13.1], and it amounts to putting your content token into Intune and making one real app assignment through it before anyone experiments with Apple’s own service. Until you have read that article, leave the control alone.


Completion checklist

The organisation is verified rather than pending. Two people hold Organization Administrator and neither is a shared mailbox. The domain is verified, and you have made a deliberate decision about the TXT record rather than an accidental one: Apple states you must keep it if you verified the domain for a brand feature such as Branded Mail or Verify with Wallet on the Web, and that you may remove it if you verified for federated authentication only. Leaving it in place costs nothing and removes a way to break this later, so leave it unless you have a reason. The Organization ID is recorded somewhere procurement will find it without asking you. The Apple Customer Number is entered with leading zeros stripped, or you have confirmed there is nothing to enter. The sixty day date is off the calendar because it no longer applies. And nobody has touched built in device management.

The next article works out who else should be able to sign in here, and what each of them can break.


Apple Business
‹ Previous: [AB 2] Getting an Organization: Two Methods, and the D-U-N-S You No Longer Need
Next: [AB 3] Roles, Organizational Units, and Who Can Break What