[AB 6.1] Build Sheet: Linking Suppliers and Carriers

By the end of this you have your Organization ID in the hands of every supplier who sells you Apple hardware, their Reseller Numbers in your tenant, a durable record of which opaque number belongs to whom, a monitored feed of Apple's five order progress messages, and a single test device that proves the whole chain works before you order two hundred.


This is the step in an Apple Business build whose duration is controlled by somebody who does not work for you. Everything else in Wave 1 can be done in an afternoon. Getting a carrier to associate your billing profile with their Reseller Number is a ticket in a queue at Verizon, and the only published lead times for it come from documents written six years ago. Start it first.

The worked estate is CatSnackJack, a hundred and forty seats with a verified Apple Business organization from [AB 2.1], a federated catsnackjack.com domain from [AB 5.1], and two supply channels that nobody has ever written down: iPhones on a Verizon business contract accumulated over four years, and Macs bought direct from Apple against a purchase order that finance raises once a quarter. That combination is ordinary and it needs two supplier entries of two different kinds.

Prerequisites. An Apple Business organization past verification. An Apple Business role whose permissions include adding Apple Customer Numbers and Reseller Numbers, and viewing the organization’s details. On the carrier side, an account with enough standing to raise an enrolment request, which in practice means either your account team or somebody in finance who is named on the contract. For step 7 you need the Transport Rules role in Exchange Online, which the Records Management and Compliance Management role groups hold by default, or the Exchange Administrator role in Entra ID if you would rather not work in Exchange RBAC. Plus the ability to create a shared mailbox.

Timing. Steps 1 to 5 take twenty minutes. Step 6 is the one with a queue behind it and I would budget two weeks and be pleasantly surprised. Step 9 needs a real order to have shipped, so it cannot be completed the same day unless you already have one in flight. Do not schedule the Intune connection in [AB 7.1] on the assumption that step 6 will land on time.

Naming convention. Apple does not let you label anything here. The supplier list is a set of opaque alphanumeric strings tagged with a type, and six months from now nobody will know which one is the carrier. Three artefacts therefore need names of your own, and all three outlive whoever creates them.

ArtefactConventionCatSnackJack value
Supplier register, one row per number entered in Apple BusinessType, entity, number, date entered, who arranged it, and the carrier-side account the arrangement coversA row for the Verizon Reseller Number and a row for the Apple Customer Number, held in the same place as the rest of the platform runbook
Order feed mailboxNamed for the job, not for Apple, so its purpose survives the rename that will eventually happen to Apple as well[email protected]
Mail flow ruleJob plus year, because you will create a second one when the first is superseded and you should not have to guess which is liveApple Device Order Reports 2026

Step 1. Read your Organization ID

In Apple Business, sign in as a user whose role has permission to view the organization’s details, then go to Settings, then Organization, and find your Organization ID under Details. Select Copy to put it on the clipboard.

Expected result: a value you can paste. Put it in the supplier register straight away, because you are about to send it to two organisations and you want the record of what you sent them.

Do not print your Organization ID in a runbook that leaves the organisation. It is not a secret in the cryptographic sense and Apple treats it as shareable, but it is the credential that authorises a third party to submit devices against your organization, and it is the same value app developers use to target Custom Apps at you. Treat it the way you treat a tenant ID: not confidential, not published either.


Step 2. Establish which suppliers you actually have

This is a purchasing conversation and it is the part most builds skip. You are looking for every route by which Apple hardware has entered the organisation in the last two years, because the carrier look-back windows make that history worth recovering.

Ask three questions of whoever raises purchase orders. Which suppliers have we bought Apple hardware from. Do we have an account number with Apple itself, and if so which department holds it. And is there a mobile contract whose devices come in on the phone bill rather than through procurement, because that one will not be on their list.

For CatSnackJack the answers were a Verizon business account nobody in IT had ever seen, a quarterly purchase order to Apple, and one MacBook Pro bought at retail in an emergency that will not appear in either. That last one is normal and it is [AB 6.2]‘s problem, not this article’s.

Check each named supplier against Apple’s list before you plan around it. Apple publishes Preferred Device Enrollment Resellers by region, and a supplier who is not on it cannot submit devices no matter how willing they are. Note the classification as well as the presence, because in the United States T-Mobile is listed as a Reseller while AT&T and Verizon Wireless are listed as Carriers, and the classification is a clue to how much process documentation you will find.

Expected result: a list of suppliers, each confirmed present on Apple’s list, each with a named human on the other side. If a supplier is not on the list, the decision in front of you is a procurement decision and it should be escalated as one.


Step 3. Obtain each Reseller Number, in writing

Apple does not publish Reseller Numbers. Its own instruction is that if you do not know your supplier’s number you should contact them, and every reseller I checked follows the same pattern: the number is issued to the customer by a representative on request and appears in no public document.

The two large United States carriers are the exception, because both have published theirs inside their own enrolment paperwork.

SupplierReseller NumberWhere it comes fromConfidence
Verizon Wireless19DA1870Verizon’s Mobile Device Enrollment Program document for Apple Business Manager and Apple School Manager, copyright 2020, and the same value in its July 2018 predecessor, which is the one actually titled an enrolment instructions and candidate information formTwo Verizon documents agree. The newer predates the Apple Business rename by six years and the older by eight
AT&T722D390AT&T Device Management Program enrolment job aid, document ID 579401 - 012523One AT&T document, January 2023
T-MobileNot publishedNowhere. T-Mobile’s only Apple Business artefact is a December 2022 disclosure and authorisation with no identifiers in itObtain by telephone from the number on Apple’s reseller list

Use those two as a cross-check rather than as gospel. Ask your representative for the number, and if what they give you differs from the table, theirs wins and mine is stale. Get it in an email rather than on a call, because the number goes into a field with no label next to it and the email is the only thing that will tell a future administrator what they are looking at.

Expected result: one Reseller Number per reseller or carrier, each with a written source, all recorded in the supplier register from the naming convention.

For the direct-from-Apple path you need an Apple Customer Number instead, and Apple’s instruction is to ask your purchasing agent, your finance department or your Apple account team. There is no self-service lookup. It is not the same number as your GSX account number, and the two get confused often enough that Apple says so on the page.


Step 4. Add the first supplier

Verification gate, and it is here because Apple documents no way out. Before you enter anything, confirm each number against the written source from step 3, and confirm that the leading zeros have been stripped from any Apple Customer Number. Apple states the zero rule twice in its own documentation and the field will accept the wrong value without complaint. More importantly, Apple documents no procedure for removing a Reseller Number or an Apple Customer Number once it is in the list. There is no delete step on the suppliers page, no mention of one in the glossary, and none in the release notes since April. Treat every entry as permanent until somebody demonstrates otherwise, which means checking the value twice rather than assuming you can tidy up later.

Sign in as a user whose role has permission to add Apple Customer Numbers and Reseller Numbers, then go to Devices, then Inventory, and select Get Started. Select the checkbox to agree to the Apple Business terms if it is offered. Select a Customer Number type, enter the number, then select Continue.

SettingValueWhy
Customer Number typeReseller for a reseller or a carrier. Apple (Direct) for your own Apple Customer Number.The two types behave differently. Apple (Direct) makes Apple surface your own order history. Reseller authorises a third party to submit on your behalf, which is a delegation rather than a lookup.
NumberThe value from step 3, verbatimApple documents no validation beyond format, and there is no reason to think it can tell a correct Reseller Number from a well-formed wrong one. Note also Apple’s glossary rule that you add each supplier to your account only once.
Terms checkboxSelectedApple qualifies this one with “if necessary”, which in practice means it appears when the Apple Business terms have not yet been accepted. If it is absent, somebody has already accepted them.

Expected result: the number appears in the inventory supplier list, tagged with its type. Nothing else changes. No devices arrive, and nothing will arrive until step 6 is complete at the supplier’s end, which is the single most common misreading of this screen.

Failure mode: doing only this step, and then reporting to a project meeting that the supplier is linked. Half a credential is not a credential. Apple even has a message for this state and it is covered in step 10.


Step 5. Add the remaining suppliers

The subsequent path is a different control with a different confirm button, which is the kind of inconsistency that makes people think they are on the wrong screen. Go to Devices, then Inventory, and select Add. Select a Customer Number type, enter the number, then select Add again to confirm. There is no terms checkbox on this path.

Multiple numbers of both kinds are supported and Apple documents no limit on how many, with one constraint from the glossary worth carrying: you add each supplier to your account only once. For CatSnackJack that is the Verizon Reseller Number entered in step 4 and the Apple Customer Number entered here, so two rows, two types.

Expected result: every supplier from step 2 present in the list with the correct type. Update the supplier register with the date each was entered and by whom, because Apple’s audit view will not tell you why a number exists and your successor will want to know.


Step 6. Register your Organization ID at the supplier’s end

Verification gate before you send anything, because this one is a delegation you cannot revoke. Handing your Organization ID to a supplier authorises them to submit devices against your organization, and Apple names an Apple Authorized Reseller among the entities that can also release a device from your organization. There is no per-supplier control over that. Before you send the identifier, confirm that the supplier is on Apple’s list, that the entity you are dealing with is the one on the list rather than a subsidiary or a franchise, and that whoever is arranging this on your side has authority to make that delegation. For a large reseller this is a formality. For a small regional partner it is not.

What each supplier wants differs, and the two carrier processes are worth setting out because their documentation is scattered.

Verizon

Verizon offers two routes and pushes you towards the self-service one, which is not how most write-ups describe it. If your primary contact is a registered My Business for Wireless user, go to Manage Account, then Product Tools, then View All, then Verizon Mobile Device Enrollment Programs, and enable automation at either the enterprise level or the billing account level. Everyone else falls back to the manual enablement request, which is the candidate information form, and that is where the screenshots below come in.

The form asks for the business name, a named point of contact with an email address, the Verizon profile identifier that Verizon calls the ECPD ID, the billing account numbers to cover, and screenshots evidencing both your Organization ID in Apple Business and Verizon’s Reseller Number in your supplier list. The completed form goes to Verizon’s Apple device enrolment mailbox, [email protected].

File provenance matters here and it is easy to get sloppy about. Those two screenshots are the only evidence Verizon has that the exchange is legitimate, they contain your Organization ID, and they are about to leave your tenant as email attachments to a shared mailbox at a carrier. Take them from a browser session on a managed device, send them from a named account rather than a shared one, keep a copy of exactly what you sent in the supplier register, and record the date. When somebody asks in eight months why Verizon is submitting devices to your organization, that record is the answer.

Verizon’s stated timings, from a document copyrighted in 2020: once the arrangement is live, IMEIs are transmitted to Apple the day after the order ships. Manual requests for devices already purchased are quoted at three business days. The 2018 predecessor says three to five for the same thing. Neither number has been restated since the Apple Business rename and you should treat both as indicative.

AT&T

AT&T runs this through its Business Console, which is the same shape as Verizon’s self-service tool. You enter your Organization ID into the console and then select which Foundation Account Numbers the arrangement should cover, which is the same shape of decision as Verizon’s billing account list and is where a multi-entity organisation gets it wrong by covering one FAN and not the others.

AT&T’s job aid states that existing devices are enrolled into the programme within twenty-four hours, and its current business page adds that devices are usually submitted when they ship from the warehouse, with a device bought in an AT&T retail store or enrolled manually taking up to a business day. The two-year look-back for previously purchased devices comes from AT&T’s older programme brief, and it is the most valuable single facility in this whole article for an estate with history.

Note that AT&T now brands this the Device Management Program. Older material, including its own 2018 brief, calls it the Device Enrollment Enablement Program. Same programme, and the rename was not announced anywhere I could find, so do not conclude you have the wrong document.

T-Mobile, and anybody else

There is no documented process. Call the number Apple publishes against T-Mobile on the reseller list, ask for the Reseller Number and for whatever their equivalent of the Verizon form is, and put the outcome in the supplier register because you are now the documentation. Expect to be asked for your Organization ID and for the billing accounts to cover, because every version of this process asks for those two things.

Expected result across all suppliers: written confirmation from each that the arrangement is live, naming the accounts it covers. Not a verbal yes. The accounts it covers is the detail that will be wrong.


Step 7. Turn Apple’s five emails into a feed

Apple’s only signal about supplier submissions is email. Five message types, from [email protected], timestamped in Greenwich Mean Time, sent to every user whose role carries the permission to add Apple Customer Numbers and Reseller Numbers. There is no queue in the portal, no pending filter and no badge. If the two people holding that permission are on leave in the same week, the Devices Pending message telling you a hundred iPhones are stuck goes to two out-of-office replies.

The fix is a copy of that mail into a mailbox somebody actually watches. This is mechanically similar to the roster rule in [AB 4.1] and materially different in what it touches: that rule copied mail addressed to your users during a capture window and needed a privacy conversation, whereas this one copies operational mail Apple sends to administrators and is permanent.

Create the shared mailbox named by the convention. Then in the Exchange admin center go to Mail flow, then Rules, select Add a rule and Create a new rule, and configure it.

SettingValueWhy
NameThe rule name from the conventionYear in the name so a successor rule does not create ambiguity.
ConditionThe sender address is [email protected]Scope to the exact sender rather than to the Apple domain. Apple sends account notifications to your users from other subdomains and none of them belong in an operations mailbox.
ActionAdd recipients, then to the Bcc box, then the shared mailboxBcc rather than redirect, so the individuals who are supposed to receive it still do. You are adding an observer, not replacing the recipients.

Turn the rule on, because Microsoft creates it switched off. Every new mail flow rule defaults to Off. Select the rule on the Rules page and enable it from the details panel. Then allow for propagation, which Microsoft states can take thirty minutes or more.

For anyone who would rather do this from a terminal, Exchange Online genuinely has a command surface for both objects and the whole of step 7 collapses into three lines. Substitute your own domain; nothing here is derived from a value you have to look up.

Connect-ExchangeOnline

New-Mailbox -Shared -Name "Apple Device Orders" -DisplayName "Apple Device Orders" -PrimarySmtpAddress "[email protected]"

New-TransportRule -Name "Apple Device Order Reports 2026" -FromAddressMatchesPatterns "^noreply@email\.apple\.com$" -SenderAddressLocation HeaderOrEnvelope -BlindCopyTo "[email protected]" -Enabled $true

Get-TransportRule -Identity "Apple Device Order Reports 2026" | Format-List Name,State,FromAddressMatchesPatterns,BlindCopyTo

Two things about that. The condition is a pattern match rather than a sender lookup, because Exchange’s sender condition resolves against mailboxes, mail users and mail contacts in your own directory, and Apple’s notification address is none of those. And the explicit enable on the third line is redundant, because the cmdlet creates the rule enabled by default, which is the opposite of the browser. Leave it in anyway. The whole reason this article prints a command is that the two surfaces disagree about the most consequential property of the object, and a reader who has just been told to check a toggle in the portal should not have to guess.

Expected result: the last line reports State: Enabled. Prove it end to end before you rely on it, by having somebody outside the tenant send a message to a user in it and confirming a copy lands in the shared mailbox. A rule that was still propagating when your supplier’s first submission landed gives you a gap you have no way to detect.


Step 8. Set the default device assignment, once there is something to assign to

Verification gate. This step requires at least one device management service to exist. That can be Apple’s built-in service or the external service you connect in [AB 7.1]. In an Intune estate it should be the second, and you should read the gate in step 2 of that article before switching the built-in service on for any reason. If neither exists yet, note this step and return to it. The reason it lives in this article rather than that one is that it is a property of how devices arrive rather than of how they are managed.

Go to Devices, then Management Services, then either select Default Device Assignment and choose a service for each device type, or select an existing service and use Edit under Default Device Assignment to attach device types to it. Select Save.

Expected result: any device added after you save is automatically assigned to the chosen service for its type. Apple’s own sentence is the important one and it is easy to skim past: existing devices are not covered. The setting is strictly forward-acting and it will never reach back over the two hundred devices your carrier just back-filled.

That asymmetry is the argument for doing the carrier registration and the Intune connection in the right order. Devices that arrive after both are done need no human intervention at all. Devices that arrived in between need a bulk assignment, which is not hard but is a step somebody has to remember.


Step 9. The end-to-end test

Order one device through the channel you have just linked. One, not a batch, and the cheapest thing the supplier sells that both Apple and the supplier will carry. Those are different lists. Apple’s automatic list runs to iPhone, iPad, Mac, Apple TV, Apple Vision Pro and Apple Watch, while AT&T’s programme excludes Mac, Apple TV and wearables outright. For a carrier link, test with a handset. The entire point is to discover that the arrangement covers the wrong billing account while it costs you one device rather than two hundred.

Then watch for four things in order.

StageExpected outputWhat it proves
Devices Submitted message in the shared mailboxNames the supplier, gives the order number and the receipt timestamp in GMTThe supplier’s fulfilment system is submitting against your Organization ID. Step 6 worked.
Devices Available messageSame order number, states the devices are now in Apple BusinessApple accepted the submission against a Reseller Number you have entered. Steps 4 and 5 worked.
The device in Devices, then Inventory, found by filtering on SourceThe device appears with a Source of Apple Authorized Reseller or Authorized cellular carrier, and the order number is searchableThe register holds a real record with real provenance, not a placeholder.
The device record itselfModel, serial number, part number, storage size, IMEI and MEID for a cellular device, and the date it was addedApple has the full identity, which is what the enrolment pane in Setup Assistant will depend on.

Take CatSnackJack as the illustration. The first Verizon submission arrives the day after the handset ships, exactly as Verizon’s document says it will, and the useful surprise is that only one of the two billing accounts turns out to be covered. That is a fifteen minute fix when you find it on device one and a fortnight of confusion when you find it on device two hundred.

If you cannot wait for a real order, the weaker substitute is to ask the supplier to back-fill a single serial number you already own. Verizon quotes three business days for a manual request and AT&T quotes twenty-four hours for existing devices, so this is not slower than waiting for a shipment and it tests slightly less: it proves the identifier exchange without proving that the automatic path fires on new orders.


Step 10. When it does not work

Apple’s five messages are also the diagnostic, which is the one genuinely good thing about the design.

SymptomDiagnosisAction
Devices Pending message receivedThe supplier submitted against your Organization ID and the matching Reseller Number is not in your listComplete step 4 or 5 for that supplier. Apple’s own message adds that you should contact support if you did not authorise the submission, which is worth taking seriously: an unexpected Devices Pending is somebody submitting devices against your organization.
Submission Error message receivedApple rejected something in the submission and does not say whatApple explicitly hands this back to the supplier. Quote the order number and the timestamp to them; you have no further diagnostic surface.
Devices Removed message receivedDevices from a prior order have been withdrawnUsually a return you initiated or a correction. Confirm with the supplier before assuming it is a fault, and check whether the removal was expected against your own returns record.
No message at all, order shipped days agoMost likely the arrangement covers a different billing account or FAN from the one the order was raised againstGo back to the supplier with the order number and ask which account it billed to, then compare against the accounts named in the written confirmation from step 6.
Device visible but with no Source you recogniseThe device entered by a route other than the one you thinkCheck the Source value against the five Apple documents, which are Apple, Apple Authorized Reseller, Authorized cellular carrier, AppleCare for replaced devices, and Apple Configurator for manual adds. Apple is inconsistent with itself here and one of its own pages renders the third as Apple Authorized cellular carrier. A device that arrived as an AppleCare replacement is a different lifecycle event and its order number begins with R.

One diagnosis Apple does not document at all: an order submitted to the wrong organization. If a supplier holds Organization IDs for several of their customers and submits yours against somebody else’s, there is no Apple guidance for recovery and no practitioner account of it that I could find. It is the argument for keeping the written confirmation from step 6 and for checking the first order rather than assuming.


Why there is no command line here

Everything in steps 1 through 6 and step 8 is browser work, and that is the product rather than an omission in this article. The Apple School Manager and Apple Business APIs are real and they have a substantial write surface: they create, update and delete device management services, Blueprints and Configurations, and they assign and unassign devices. Suppliers are simply not on it. There is no supplier collection and no create, update or delete for a supplier of any kind.

What the API does give you is provenance, and it is worth an annual reconciliation. Every device resource carries a purchase source type, which is Apple, reseller or manually added, and a purchase source ID, which Apple documents as the Apple Customer Number or Reseller Number the device arrived on. Enumerating your devices therefore tells you which suppliers are actually submitting against your organization, which is the supplier register from the naming convention, generated rather than maintained. That is the one part of this article a script can check.

Step 7 is the exception because it is Microsoft’s product rather than Apple’s, and Exchange Online has a genuine cmdlet for both objects. That is the pattern this series follows throughout: a command appears when the product has one.


Completion checklist

The Organization ID is recorded and has been sent to every supplier, with a record of what was sent and when. Every supplier from the purchasing conversation is confirmed present on Apple’s reseller list. Every Reseller Number has a written source, and every one is in the tenant with the correct Customer Number type. The Apple Customer Number is entered without its leading zeros. Each supplier has confirmed in writing that the arrangement is live and has named the billing accounts it covers. The order feed mailbox exists, the mail flow rule is enabled rather than merely created, and a test message has proven it. One real device has travelled the whole chain from order to inventory record, and the Source value on it is the one you expected. The supplier register is written down somewhere that is not this browser tab.

What remains is the hardware that was never going to arrive through a channel: the retail purchase, the device inherited in an acquisition, the handset somebody’s predecessor bought on a personal card and expensed. [AB 6.2] brings those in, on a claim you make yourself and that Apple hedges accordingly.


Apple Business
‹ Previous: [AB 6] How Devices Enter: Customer Numbers, Reseller Numbers, and the Carrier Channel
Next: [AB 6.2] Build Sheet: Adding Owned Devices with Apple Configurator