Apple Business does not record that you own a device. It records that somebody sold it to you. That distinction sounds academic until the week you discover that the forty iPhones sitting in your stockroom are invisible to the system that is supposed to provision them, and that no amount of administrative authority in your own tenant will make them appear.
The device register is the part of Apple Business that people assume they understand and then get wrong at scale. [AB 1] made the case that Apple Business is the system of record for device ownership, organizational identity and licence entitlement. This article is about the first of those three, and about the fact that the record is written by your supplier rather than by you.
The register records provenance, not possession
Read Apple’s own conditions for a device appearing automatically and the design becomes obvious. If you buy direct, the purchaser needs to have used an enrolled and verified Apple Customer Number at the time of the order. If you buy through a reseller or a carrier, that seller needs to link the device to their Reseller Number and submit it. The device needs to have been ordered after 1 March 2011 and to meet minimum operating system requirements. And Apple adds a qualifier to that date which is the mechanism behind every carrier look-back window: the reseller’s or carrier’s own sales history determines the actual date of eligibility, because their accounts may not keep records going back that far.
Every one of those is an assertion about a transaction that has already happened. None of them is an action you can take while holding the hardware. There is no serial number field into which a determined administrator can type their way to ownership, because a serial number is not evidence of anything. Anybody can read a serial number off the back of a device they are holding, and a system that accepted serial numbers as proof of ownership would let a thief enrol your fleet into their tenant.
The purchase record is the authentication. Everything else in the device half of Apple Business is downstream of a claim made by whoever took your money.
This is why the supply chain matters architecturally rather than administratively. Apple has built an ownership model in which the party attesting to your ownership is your supplier, and your supplier’s willingness and ability to make that attestation is a procurement question dressed as a technical one. When somebody in finance switches to a cheaper reseller who is not on Apple’s list, they have made a device management decision, and nobody in the conversation will have known it.
Apple Configurator is the exception, and it is instructive precisely because Apple treats it as one. A device added with Configurator enters on a claim you made yourself, in physical possession of the hardware, and Apple hedges that claim by giving the eventual user a thirty day window in which they can walk the device straight back out again. Apple attaches no such window to purchase channel devices and never explains why, though the reason is not hard to guess. [AB 6.2] works that path end to end.
Three identifiers, and the direction each one travels
Most of the confusion in this area comes from people treating three different identifiers as variants of one thing. They are not, and the cleanest way to hold them apart is by which way they move.
| Identifier | Whose it is | Direction | What it authorises |
|---|---|---|---|
| Organization ID | Yours, issued by Apple | You hand it out | A named supplier to submit devices against your organization. Also used by app developers distributing Custom Apps to you. |
| Reseller Number | The supplier’s | You take it in | Apple to accept that supplier’s submissions on your behalf. |
| Apple Customer Number | Yours, issued by Apple | You take it in | Apple to surface your own direct purchase history. Not the same thing as your GSX account number. |
The exchange is bidirectional and both halves are load-bearing. You give the supplier your Organization ID and you enter their Reseller Number in your own tenant, and until both of those have happened and Apple has verified the pair, nothing flows. AT&T states the failure from the other side of the counter, in its own enrolment job aid: if the customer enrols in the programme and does not add the AT&T Reseller ID, device information cannot be processed. Two organisations each hold half of a credential, and the half you are not responsible for is the one you will forget.
The Apple Customer Number carries one piece of operational trivia that Apple repeats on at least two pages and that costs people an afternoon: omit any leading zeros when you enter it. Finance will give you the number with the zeros. Apple wants it without them.
Apple’s glossary adds a condition the suppliers page leaves out, which is that the direct purchase path is defined as buying from Apple using a purchase order. That is a small phrase with a large consequence for anybody who thought a corporate card at the online store would do, and it is the first hint of the retail problem I come to below.
Whether it is automatic depends on which Apple page you are reading
Apple currently says both things. The device workflow page states that once the linking is complete, orders of iPhone, iPad, Mac, Apple TV, Apple Vision Pro and Apple Watch appear automatically in Apple Business. The suppliers page, describing the same arrangement, ends its explanation of the identifier exchange with a parenthetical that says it will not happen automatically. Both pages carry the same published date.
The reconciliation, and I am reasoning here rather than quoting, is that the two sentences are describing different actors. The suppliers page is telling you that Apple does not go looking for your orders and that your reseller must actively submit them through their portal, which is a business process at their end that somebody has to configure. The workflow page is telling you what your experience looks like after that process is running. Both are true and Apple never says so.
The practical reading is the one that should shape your expectations. A supplier link is a standing arrangement with a fulfilment system at the other end, not a setting you toggle. It can be configured for one billing account and not another. It can be configured for new orders and not for the two hundred devices you bought last year. It can quietly stop when the carrier migrates you to a new account structure. None of those failures produce an error in your tenant, because your tenant is not the thing that broke.
The carrier channel, which is where the iPhones actually come from
Deployment writing tends to assume a clean reseller story: a purchase order to CDW or SHI, a bulk shipment, serials in the register before the boxes arrive. That is a real world and it is not the world most mid-sized organisations live in. CatSnackJack, the worked estate I have used since the on-premises series, is a hundred and forty seats that bought iPhones piecemeal on a carrier contract over four years, because that is how phones get bought when the phone bill and the IT budget are different budgets.
Apple maintains a list of Preferred Device Enrollment Resellers, updated in June 2026, and its classifications are worth reading carefully because they are not what you would guess. In the United States, AT&T and Verizon Wireless are classified as Carrier. T-Mobile appears on the same list, once, classified as Reseller. Canada lists Bell, Rogers and TELUS all as Carrier, and Apple’s Mexican listing classifies AT&T as Carrier, so the T-Mobile entry looks like a per-row decision rather than a regional convention.
What the three of them actually publish is wildly unequal, and pretending otherwise does the reader no favours.
| Verizon | AT&T | T-Mobile | |
|---|---|---|---|
| Apple’s classification | Carrier | Carrier | Reseller |
| Operative document | Enrolment instructions and candidate information form, copyright 2020 | Device Management Program enrolment job aid, document ID 579401 - 012523, January 2023 | A disclosure and authorisation PDF dated 6 December 2022 |
| Reseller Number published | 19DA1870 | 722D390 | Not published anywhere |
| What you supply | Organization ID, Verizon profile ID (ECPD), billing account numbers, screenshots of both identifiers | Organization ID entered in the AT&T Business Console, then the Foundation Account Numbers to cover | Nothing documented |
| Stated timing | IMEIs the day after the order ships; manual back-fill requests three business days | Existing devices enrolled within 24 hours | Nothing documented |
| Process documentation | Yes, and six years old | Yes, and three years old | None |
Verizon’s document is the one people cite and it is a museum piece. There is an older predecessor dated July 2018 that gives the same Reseller Number, asks for a DEP Customer ID rather than an Organization ID, and quotes three to five business days for back-fill against the newer document’s three. Both predate the Apple Business rename, one by six years and one by eight. Neither has a successor that I could find, though the enrolment mailbox in them was still being cited in customer-side documentation as recently as May 2025, which is evidence the process is live rather than abandoned. What does not exist is an HTML page, a changelog or a named owner: those two PDFs, still hosted on verizon.com, are the only place the identifiers appear. If you are working from Verizon documentation in 2026 you are working from an artefact, and the only sensible posture is to treat its numbers as a starting point and confirm them on the call.
AT&T is in better shape and is the only one of the three whose current business page uses the post-rename product name. Its programme is now branded the Device Management Program rather than the Device Enrollment Enablement Program that its 2018 brief describes, which is a naming change nobody announced and which will make you doubt you have the right document. That 2018 brief is also the source of the two-year look-back for devices already purchased, a genuinely useful facility that Verizon does not put a window on. AT&T’s current page adds a detail worth having: devices are usually submitted when they ship from the warehouse, and a device bought in an AT&T retail store, or one enrolled manually, can take a business day to appear.
T-Mobile deserves to be described accurately rather than diplomatically. It is on Apple’s list, so the capability exists. What it publishes is a single legal instrument, dated December 2022, telling a customer that T-Mobile may provide device information to Apple on request and disclaiming any responsibility for what Apple then does with it. There is no Reseller Number, no form, no identifier list, no lead time and no process page. The URL Apple publishes against T-Mobile on its own reseller list now redirects to a handset promotion page with no mention of Apple Business or its predecessor anywhere on it. The route in is the telephone number in Apple’s list. An organisation standardising on T-Mobile should plan for a conversation rather than a procedure, and should get the Reseller Number in writing from whoever answers.
Structurally the three are the same shape. The carrier holds a Reseller Number, you register your Organization ID with them once, and their fulfilment system pushes serials to Apple as orders ship. What differs is how much of it they have written down, and what they will carry. AT&T’s programme excludes Mac, Apple TV and wearables outright, along with bring-your-own devices, refurbished and certified like-new stock, and anything supplied through a third-party warranty or insurance company. So the carrier channel and Apple’s automatic list are not the same list, and an organisation buying Macs on a carrier account is buying them outside the mechanism.
The only monitoring Apple gives you is an inbox
When a supplier submits an order on your behalf, Apple sends mail. Five kinds of it, from [email protected], all timestamped in Greenwich Mean Time regardless of where your organisation is.
| Subject | What it means |
|---|---|
| Devices Submitted | The supplier has sent the order to Apple. Apple has received it. Nothing is available yet. |
| Devices Pending | The supplier submitted against your Organization ID, and you have not added their Reseller Number. The devices exist and are unavailable. |
| Devices Available | The devices are in Apple Business. |
| Submission Error | Something was wrong with the submission. Apple tells you to follow up with the supplier and offers no detail of its own. |
| Devices Removed | Devices from a prior order have been taken back out, typically a return or a correction by the supplier. |
Devices Pending is the state worth understanding, because it is the one that describes a half-completed exchange. A carrier can successfully submit devices against your Organization ID before you have entered their Reseller Number, and the result is not an error. The devices sit in a holding state, invisible in your inventory, waiting for you to complete your half. Apple’s message says exactly that, and adds a line telling you to contact support if you did not authorise the submission.
Now notice what is missing. Apple documents no in-portal view of pending submissions. There is no queue, no badge, no filter for devices in limbo. The pending state exists in an email and nowhere else, and that email goes to everyone whose role carries the permission to add Apple Customer Numbers and Reseller Numbers.
Notification is scoped to a permission rather than to a role, and Apple has fixed both ends of that in a way worth knowing. Every Organization Administrator and every IT Administrator holds the permission on an always-on basis and cannot be removed from the distribution. Device Enrollment Manager, the predefined role you would expect to want it, has it off by default. So the recipient list is whoever holds your two most senior roles plus whatever you deliberately added in [AB 3], and the failure mode is not that nobody receives it. It is that an inventory message lands in the inboxes of the people least likely to act on one.
That is a monitoring architecture decision Apple has made on your behalf, and it is a poor one. The correct response is to stop treating those messages as notifications to individuals and start treating them as a feed, which is what [AB 6.1] builds.
The retail trap
Somebody in your organisation has walked into an Apple Store with a company card and bought a MacBook Pro because the lead time on the proper channel was three weeks. That device has no Apple Customer Number attached to it and no reseller behind it, so it produces no claim, so it does not exist as far as your register is concerned. This happens in every estate and it happens most in the estates that are otherwise well run, because the pressure to go around procurement is proportional to how rigorous procurement is.
Apple documents no way to attach that purchase retroactively. I want to be exact about the strength of that statement, because there is a difference between a prohibition and a silence and this is a silence. Apple’s requirements page describes automatic addition as conditional on the purchaser having used a verified Apple Customer Number at the time of the order, its glossary frames the direct path as a purchase order, and its release page names only two routes back in for a device that has left: Apple Configurator, or asking the reseller or carrier that sold it to you to submit it. Nowhere does Apple say a retail purchase cannot be associated later. It simply never describes a mechanism.
The field fills that silence, and its answer is more interesting than a flat no. A March 2022 Jamf Nation thread, describing the pre-rename interface, opens with a contributor stating flatly that an Apple retail store cannot do this. A former Apple retail employee then contradicts him: work with the store’s Business Team and the devices do get added, and where a store does not know how, an Apple enterprise account representative will make the introduction. Not every store has such a team, and his advice is to ring the larger metropolitan stores ahead. The same contributor adds a warning I would repeat to any client, and it is the most useful sentence in the thread: tell nobody beyond the people who need to know, because what spreads internally is not the deployment capability but the corporate discount, and you end up with an employee’s family’s devices in your MDM and no way to work out how they got there.
The counterweight is a July 2025 thread on Apple’s own community site in which a customer who bought Macs on the online store under a business account could not obtain an Apple Customer Number at all, and was told by Apple support to cancel the order. That thread closed unresolved. It is worth noting that the poster is quoting Apple rather than folklore: the line he found, telling a customer who buys from an Apple Store to ask the Business Team for their Apple Customer Number, is not on Apple’s current suppliers page. Apple used to document the retail route and no longer does, which is a stronger fact than anything in the forum thread.
So the recovery order for a device already in the building is: ask the seller to submit it retroactively, which AT&T’s two-year look-back makes concrete and which Apple explicitly endorses for reseller and carrier purchases; and failing that, Apple Configurator. The second of those is not a lesser version of the first. It produces a device record with a different provenance and a thirty day escape hatch attached to it, and the difference matters enough that it has its own build sheet.
One device type has neither recovery route. Apple Watch is on the list of devices that appear automatically through a supplier, and it is absent from every manual add path Apple documents. AT&T excludes wearables from its carrier programme on top of that. A watch bought outside the channel has no way into the register at all, which is worth knowing before somebody promises to manage them.
The exits, and which of them are one way
Devices leave the register by being released. Apple’s confirmation dialog makes you tick a box reading that you understand this cannot be undone, and the prose two paragraphs above that dialog, on the same page, tells you that you can always add devices back. [AB 3] already flagged that contradiction and I still cannot resolve it from documentation. The reading that fits both sentences is that the release event and the Released status are permanent while the serial number can re-enter as a new record through Configurator or a reseller resubmission, but Apple does not say so and I am not going to pretend it does.
Three consequences are unambiguous, and one of them is the most expensive available mistake in this product.
Managing Activation Lock through Apple Business becomes impossible once a device is released. A released device needs to be erased and restored. And you must not release a device that is going to Apple for repair, because if Apple replaces it the replacement will not be available in Apple Business. Apple’s own instruction for the service case is to unassign the device from its device management service, not to release it, and replacement units come back on an order number beginning with the letter R, which is how you find them afterwards. Somebody clearing down the register before a batch of warranty repairs, doing what looks like good hygiene, can permanently remove a dozen replacement devices from your estate before they have been manufactured.
Unassign for repair. Release for disposal. Getting those two round the wrong way costs hardware, and there is no undo.
The governance point is who is allowed to do it, and Apple gives two different answers depending on which of its own documents you read. The user guide names three entities that can release a device: a user with the relevant permission, a linked device management service that has been granted the ability, and an Apple Authorized Reseller. Apple’s API documentation is less tidy and enumerates five release entity types, adding a release performed through the API and a release triggered by a replacement, with matching attributes on the device resource to record which one acted. That discrepancy is itself the finding. The set of things that can remove a device from your register is larger than the page you would read to find out.
Only the user is an identity you manage. The device management service is a delegation you make, possibly without noticing, when you connect Intune, and [AB 7] takes that argument apart. The reseller is a delegation you made when you handed out your Organization ID, and Apple provides no control over it at all.
One thing did improve. Since 29 July 2026, users with permission to assign, unassign or release devices can see those activities regardless of who initiated them. Before that you could not reliably see an activity somebody else had started, which for a set of delegated authorities is precisely backwards. If your estate predates that change, do not expect the historical record to be complete.
What this means for how you sequence the work
The register is upstream of everything else in the device half of this platform. A device that is not in it cannot be assigned to a device management service, and a device that is not assigned to a service will never see the enrolment pane in Setup Assistant, which is the entire mechanism by which zero touch works. Apple states the dependency in one sentence: you assign a device to a service so that Setup Assistant displays the pane to enrol it in that service.
That makes the supplier link the first real deadline in an Apple Business project, because it is the only step whose duration is controlled by an organisation that does not work for you. The tenant work can be done in an afternoon. Getting a carrier to associate a billing profile with a Reseller Number is a ticket in somebody else’s queue, and the only published figures for how long it takes come from documents written before the product had its current name.
Start it early, start it before you need it, and start it before you connect anything. The next two articles do the work: [AB 6.1] for the supplier and carrier link, and [AB 6.2] for the devices that are already in the building and were never going to arrive through a channel at all.
Apple Business
‹ Previous: [AB 5.1] Build Sheet: Federation and Directory Sync, End to End
Next: [AB 6.1] Build Sheet: Linking Suppliers and Carriers ›




