[AB 6.2] Build Sheet: Adding Owned Devices with Apple Configurator

Devices that never came through a channel can still enter Apple Business, on a claim you make in physical possession of the hardware. Apple hedges that claim with a thirty day window in which the user can walk the device back out, and never says what happens on day thirty-one, though Microsoft says part of it. Here is the whole path, including the platform split that sends you to the wrong app.


Every estate has hardware that arrived the wrong way. The MacBook Pro bought at retail in a hurry, the six iPhones inherited when you absorbed a competitor, the iPad somebody’s predecessor expensed. Apple Configurator brings them into the register on a claim you make yourself, and Apple treats that claim differently from a purchase in ways that will surprise you on day thirty.

The worked estate is CatSnackJack, whose supplier links from [AB 6.1] now cover the Verizon iPhone contract and the quarterly Apple purchase order. What they do not cover is one MacBook Pro bought at an Apple Store during a hardware failure, and six iPhone 15 handsets that came with a two-person acquisition and were bought on a carrier account that no longer exists. Seven devices, two platforms, and both of them need this article.

Prerequisites. An Apple Business role carrying the permission Apple names as viewing device management services, managing default platform assignment, and adding devices with Apple Configurator. Grant the separate permission to assign devices to device management services as well, because Apple is inconsistent about which one step 9 needs: the Configurator page requires the first, while the general assignment and migration pages require the second. An iPhone running iOS 16 or later, or an iPad running iPadOS 16 or later, with the app installed and internet access. Physical possession of every device. For a Mac, Apple silicon or an Apple T2 Security Chip. For an Apple TV, an Ethernet model and a Mac. And a decision, made before you start, about whether every one of these devices is genuinely yours to supervise, because the process erases them.

Timing. A few minutes per device once you have the rhythm, in my experience two to four, plus however long an erase takes on a configured Mac, which is not two minutes. The part that takes real time is the reconciliation in step 10, and the part that takes calendar time is the thirty day provisional period, which starts later than you think and which you should understand before you hand anything to a user.

Naming convention. Apple gives you nothing to name in this flow, and the devices arrive in the register as an undifferentiated group. The artefact that needs a name is the manifest, and it is the only thing standing between you and a file called serials.txt in somebody’s downloads folder.

ArtefactConventionCatSnackJack value
Serial manifest, one file per add sessionab-configurator- then the batch identifier, then the date the session ran, in ISO order so the files sort. A plain text file, because that is what Apple’s paste expectsab-configurator-acquisition-handsets-2026-08-12.txt
Batch identifierWhy the devices exist, not where they came from, because provenance is already in the register and the reason is notacquisition-handsets and retail-recovery

The manifest is a real working artefact rather than paperwork. Apple lets you paste up to 1024 comma-separated serial numbers from a text file into the inventory search, and that paste is how you prove in one action that all seven devices landed. Write the serials down before you erase anything, because after step 5 the device is off and you are reading a label with a torch.


Step 1. Work out which app you need, because it is not the obvious one

There are two Apple Configurator applications and they support different hardware. The split is counterintuitive enough that people lose an afternoon to it. It is printed identically on the Apple Business and Apple School Manager pages, which are the same topic forked between two guides, and again on an Apple Platform Deployment page last dated October 2023, so it has survived more than two years and a rename. This is a design decision rather than a documentation slip.

AppiPhoneiPadMacApple TV, Ethernet models onlyApple Vision Pro
Apple Configurator for iPhoneYesYesYesNoYes
Apple Configurator for MacYesYesNoYesNo

You add a Mac with the iPhone app. You add an Apple TV with the Mac app. Neither app does both.

Two things follow that are worth knowing before you commit to a plan. Apple Configurator for iPhone runs on iPad as well, despite the name, which is useful when the only spare device is a tablet. And the iPhone app has not been updated since September 2022, sitting at version 1.1, while the Mac app shipped a maintenance release in June 2026. The frozen app is the one Apple requires you to use for Mac and for Apple Vision Pro. That is not a reason to avoid it, and it is a reason not to expect the interface to have moved since whatever guide you last read.

Apple Watch has no path here at all. It is absent from the support matrix, absent from the requirements page’s manual-add list, and absent from the device types the app offers for default assignment. A watch enters management by being paired to a supervised, managed iPhone that carries the relevant declarative configuration, which is a Phase 9 concern rather than an Apple Business one. Apple Watch does appear in the list of device types that arrive automatically through a supplier, so the asymmetry is real: bought through a channel, a watch enters the register; held in your hand, it cannot.

Verification gate. Before you download anything, confirm the app against the table for every device type in the batch, and confirm the hardware floor. A Mac needs Apple silicon or a T2 chip. An Apple TV needs Ethernet. For CatSnackJack that means the iPhone app for the MacBook Pro and for the six handsets, and no Mac app at all, which was not the answer anybody expected.


Step 2. Check the target versions, and note Apple’s error in the table

Each target device must be running at least a given version and must be sitting at a specific Setup Assistant pane. Apple publishes both in one table, with two columns and four unlabelled rows: there is no device column, and row identity is inferred from order and from the surrounding prose. That table also has a defect I am going to reproduce rather than silently repair, because a build sheet that quietly corrects its source teaches the reader to trust the wrong thing.

TargetApple’s stated minimumSetup Assistant pane to stop at
MacmacOS 12.0.1Select Your Country or Region
iPhoneiOS 16Choose a Wi-Fi Network
iPadApple prints iOS 16 again hereChoose a Wi-Fi Network
Apple Vision ProvisionOS 26Hello

Apple’s table has four rows and prints iOS 16 in two of them, on both the Apple Business and the Apple School Manager versions of the page, both dated April 2026. Read against the surrounding prose, which covers Mac, iPhone, iPad and Apple Vision Pro, the third row is plainly meant to say iPadOS 16. Apple’s own requirements sentence elsewhere on the same page does say iPadOS 16, but it is describing the iPad running the app rather than the iPad being added. Assume iPadOS 16 and be aware you are assuming it.

The enrolling device needs iOS 16 or iPadOS 16 or later, which is a separate floor from any of the above.


Step 3. Sign in and set the app up once

Launch Apple Configurator on the enrolling iPhone and sign in with the Managed Apple Account of a user whose role has permission to manage devices. Then open the app’s settings and make two decisions that apply to every device in the session.

SettingValue for CatSnackJackWhy
Network connection methodShare Wi-FiShares the enrolling iPhone’s own connection with the target. The alternatives are Configuration Profile, which needs a profile prepared in advance, and Don’t Share, which makes the person holding the target device pick a network. Share Wi-Fi is the one that works in a stockroom. Note Apple states Don’t Share is not supported with Apple Vision Pro, so a Vision Pro session must share one way or the other.
Device management service assignment methodNone on a first run, Default once Intune is connectedSee the gate below. This is the setting that decides whether step 9 is a separate job.

The three assignment options are None, which leaves the device unassigned and hands you step 9 as manual work; Default, which assigns to whatever default you configured per device type in Apple Business; and Specific, which assigns to one named service you pick.

Verification gate, and it decides your ordering. Default only works if a default device assignment exists for that device type, which requires a device management service, which requires [AB 7.1] to be finished. If you are running this article before that one, choose None and accept that you will assign by hand. If Intune is already connected, choose Default and confirm on the Apple Business side that the default for this device type points where you think it does. Note that Apple’s Default option in the iPhone app enumerates iPhone, iPad, Mac and Apple Vision Pro only, which is consistent with that app not supporting Apple TV. It says nothing about the organisation-wide default device assignment set under Devices, then Management Services, which Apple describes as per device type with no exclusions.


Step 4. Erase anything that is already configured

A new device out of a box is already at Setup Assistant and needs nothing. A device that has been in use is not, and the two device families handle this differently.

Verification gate, and this is the irreversible one in this build sheet. Erasing destroys everything on the device. Before you touch a configured Mac or a used iPhone, confirm four things. That the device is genuinely organisation-owned rather than a personal device somebody has been using for work, because this procedure is not a BYOD path and running it on somebody’s own hardware is a different kind of incident. That any data on it has been recovered or is confirmed disposable. That the person who last used it has signed out of their personal Apple Account, because Activation Lock will stop you dead. Apple Business can turn off a user-linked Activation Lock, but only for a device that was already in Apple Business when the lock was enabled, which by definition a Configurator add is not. And that you have written the serial number into the manifest, because you are about to lose easy access to the screen that shows it.

For a configured Mac, erase it yourself before pairing. Choose Apple menu, then System Settings, then General, then Transfer or Reset, then Erase All Content and Settings, and complete Erase Assistant with administrator credentials. Apple’s own warning is that erasing removes all the information from the Mac and that you should have an up-to-date backup. One documented failure: if the Mac is running a modified version of macOS, Erase Assistant cannot erase it and displays an alert telling you to reinstall macOS first.

For a used iPhone or iPad you do not need a separate erase, because the pairing flow ends in Erase and Shut Down. You do need the device back at Setup Assistant, which means erasing it by the ordinary route if it is currently sitting on a home screen.

Expected result: every device in the batch powered off, at or reachable to Setup Assistant, with its serial number in the manifest.


Step 5. Add an iPhone or iPad

Start up the target device. Continue through Setup Assistant and stop at Choose a Wi-Fi Network. Apple is explicit that if you go past that pane you must restart the device. It is the failure I see most often on a first run.

Bring the enrolling iPhone close to the target, then do one of two things. Either scan the image that appears in Setup Assistant on the target. Or, on the target, tap Pair Manually in the lower left of Setup Assistant, then in Apple Configurator on the enrolling iPhone tap Manual Pairing and enter the six-digit code the target displays.

Note the two control names, because Apple uses both in one sentence and they are not the same control. Pair Manually is on the target device, inside Setup Assistant. Manual Pairing is in Apple Configurator on the device in your hand. Getting them the wrong way round is exactly the kind of error a reader working from text alone will make, and there is nothing on either screen to catch it.

If Setup Assistant on the target does not show the pairing pane, Apple’s documented remedy is to return to the Home Screen on the enrolling iPhone and tap the Apple Configurator app again. Apple prints that remedy in the iPhone, iPad and Apple Vision Pro procedures only, not in either Mac procedure.

The serial number and other device information upload to Apple Business. Wait for the process to complete, then tap Erase and Shut Down.

Expected result: the target erases and powers off. The serial number is now in Apple Business, in a group named Apple Configurator.

Apple attaches one unlinked pointer to this whole path that is worth chasing before a large batch: it says that for manually added devices you should review the terms of use for Authorized Devices. Those terms sit in the Apple Business Agreement rather than in the user guide, I have not read them for this article, and an organisation adding hundreds of devices on a claim it made itself should have somebody who has.

Two things Apple mentions in passing that are worth carrying. If you are prompted with a proximity setup option later, ignore it. And Apple never names a radio in the pairing procedure itself. It describes bringing one device close to another, scanning an image, or typing a six-digit code, and it does not say Bluetooth. The word does appear elsewhere in the corpus, but only as a device attribute: Apple Business records a Bluetooth MAC address and lets you filter on it. Nothing states a Bluetooth dependency for pairing. If your environment has Bluetooth disabled by policy and pairing fails, that is a useful data point and it is not a documented requirement, so do not plan around one either way.


Step 6. Add a Mac

Same app, different pane, different final button. If it is a laptop, plug it into power first so it does not sleep partway through. If it will reach the internet over Ethernet, connect the cables and adapters before you start.

Start up the Mac, select the language in Setup Assistant, click Continue, and stop at Select Your Country or Region. Past that pane you restart, same as on iPhone.

Bring the enrolling iPhone close to the Mac and either scan the image in Setup Assistant, or click Pair Manually in the lower left of Setup Assistant and then tap Manual Pairing in Apple Configurator and enter the six-digit code.

Wait for the upload to complete, then click Shut Down. There is no erase step on the Mac path, because a Mac at Setup Assistant has already been erased, either at the factory or by you in step 4.

Expected result: the Mac powers off and its serial number is in the Apple Configurator group in Apple Business. For CatSnackJack that is the retail MacBook Pro finally in the register, seven months after somebody bought it in a panic.


Step 7. Apple Vision Pro and Apple TV, briefly

Apple Vision Pro uses the iPhone app and is the one target for which Apple documents no scan option. The enrolling iPhone must be set to share Wi-Fi or to supply a configuration profile, since Don’t Share is unsupported here. Start the Vision Pro, leave it at the Hello pane, bring the enrolling iPhone close, tap Manual Pairing in Apple Configurator, and enter the six-digit code that appears to the person wearing the device. Then tap Erase and Shut Down. The awkwardness of reading a code out of a headset to somebody holding a phone is a real ergonomic problem and there is no documented alternative.

Apple TV requires the Mac app, and only models with Ethernet. If your Apple TV estate is Wi-Fi only, there is no manual add path and the device must have come through a supplier.


Step 8. Prove the batch landed

This is where the manifest earns its keep, and it is also the file provenance step. The manifest was written by whoever handled the hardware, possibly in a stockroom on a different site, and it now has to reach the browser session of whoever holds the assignment permission. Move it deliberately: attach it to the change record rather than sending it in a chat message, keep the copy that was actually used, and do not retype serial numbers, because a transposed character produces a device that is silently missing from a set of seven and nobody notices until it fails to enrol.

In Apple Business go to Devices, then Inventory, and paste the manifest’s serial numbers into the search field as a comma-separated list. Apple accepts up to 1024 in one paste, from a text file. Apple documents paste only and never documents a file upload, so anyone describing a CSV import has confused this with something else.

Expected output: every serial in the manifest returns a device record, and each record shows a Source of Apple Configurator. A serial that returns nothing did not upload, which usually means the pairing was interrupted before the upload completed rather than that anything is wrong with the device. Pair it again.


Step 9. Assign the devices to a device management service

Skip this if you chose Default or Specific in step 3 and the assignment took. Verify rather than assume, because a device that is in the register and unassigned looks identical in a list to one that is assigned, until you open it.

Go to Devices, then Inventory. Select the Search Filter, select Source, select Apple Configurator, then select Search. Select one or more devices, then Assign Device Management. Apple’s Configurator page says the multi-device control is labelled Assign while its assignment page uses Assign Device Management for both single and multiple selections, so take whichever the toolbar actually offers. Choose the device management service, select Continue, read the dialog, select Confirm, then either stop or view the activity, and when it completes select Done.

Expected result: the devices are assigned. Apple adds a caution worth heeding: you may need to refresh the device list in your device management service before the newly added devices appear there. On the Intune side that is a sync, and the limits from [AB 7] apply: a manual sync no more than once every fifteen minutes, an automatic sync every twelve hours on the Apple mobile token and every twenty-four on the macOS token, and a full sync no more than once every seven days. A batch containing both a Mac and handsets is therefore working to two different clocks.

One sentence to internalise: after assigning a device to your service, it no longer uses any settings from Apple Configurator. Whatever the app was set to at pairing time stops mattering the moment the assignment lands.

An Apple-versus-Apple contradiction you have to resolve to proceed. The Apple Business guide says not to proceed with Setup Assistant on the device after you assign it to a device management service. The Apple Configurator for Mac guide, describing the same hazard, says not to proceed until you assign it. Those are opposite instructions and both pages are current. The version that makes operational sense is the second one, and Apple supports it elsewhere on the same page. Its iPhone, iPad and Apple Vision Pro procedures all end by telling you to ensure the device management service has a record of the device before proceeding with Automated Device Enrollment, which is record-before-boot in Apple’s own words. So: wait until the device is assigned and your device management service can see it, and then boot it. That is Apple’s sequencing, not my preference, even though one of Apple’s own sentences says the opposite.

For anyone building this at scale, the assignment step is the one part of this article that Apple exposes to automation. The Apple Business API can assign or unassign a device to a device management service through its device activity endpoint, which sits in a namespace untouched by the April 2026 release and therefore predates it. What April and June 2026 added was Blueprint and Configuration management and the ability to create and delete device management services themselves. The Configurator add cannot be scripted at all, because it requires physical proximity to the hardware by design, and no amount of API surface will change that. The API path is the subject of the automation build sheet later in the series.


Step 10. The end-to-end test

Take one device from the batch, ideally the one you care least about, and run it all the way to a managed state. Everything before this proves the register accepted a serial number. This proves the thing the register exists for.

StageExpected outputWhat it proves
Search the serial in Devices, then InventoryA device record with Source Apple Configurator and a date addedThe claim was accepted.
Open the device recordModel, serial number, part number, storage size, and for a cellular device the IMEI, MEID and EIDApple holds the full identity, not a stub.
Check the device management service in Intune after a syncThe serial appears in the enrollment program token’s device listThe assignment crossed the connection. If it did not, the problem is the token, not the add.
Power the device on and walk Setup AssistantThe remote management pane appears and names your organisationThis is the whole point. A device that reaches this pane will enrol.
Complete enrolment and check the device record againApple Business shows the service under the Device Management Service list on the device record, which it does not show before enrolmentThe register and the management plane now agree.

That last row is worth understanding because it generates support calls. Apple’s device list and its device record legitimately disagree during the window between assignment and enrolment. The list shows the service assignment right up until a user signs in to the device, at which point it shows the user’s name instead. The record shows no service at all until a user actually enrols. So the assignment is visible in one view before enrolment and in the other view only after it, and an administrator checking the wrong one at the wrong moment concludes the assignment did not stick.

If the remote management pane does not appear, the ordinary causes are that the device was not assigned, that it was booted past the point where the pane would show, or that an Intune-side enrollment restriction is blocking the platform. That last one presents as an invalid profile and is covered in [3.1.1].


The thirty day provisional period, and what Apple will not tell you

This is the part that makes a Configurator-added device different from a purchased one, and it is the part most write-ups get subtly wrong.

Apple’s wording is that when you give the device to a user, they have a thirty day provisional period in which they can release the device from Apple Business, from supervision and from the device management service. The user can undo your work, unilaterally, from the device in their hand.

The clock starts at successful assignment and enrolment. Not at pairing. Not at the serial upload. Not when you hand the device over. Apple states the two conditions explicitly and they are both about the device management service. The practical consequence is the opposite of what people assume: a hundred handsets added with Configurator in August and left unassigned in a cupboard have no clock running at all, and each one gets a full thirty days of user-releasable exposure on the day it finally enrols. Stockpiling does not burn the window down. It defers it.

Intune describes the same affordance from the other side and dates it differently, which matters. Locked enrollment behaves differently on devices not originally purchased through Apple Business: users can see the remove management button in the Settings app for the first thirty days after activating the device, and after that provisional period the option is hidden. So the affordance is visible, in Settings, to any user curious enough to look. But Apple dates the period from assignment and enrolment while Microsoft dates it from activation. On a device handed straight to a user those collapse to the same day. On a device stockpiled and enrolled later they do not, and I would plan against whichever comes first.

What happens on day thirty-one is not documented by Apple. I have looked. It is not on the Configurator page, not on the release devices page, not on the supervision page, not in the deployment guide, not in the release notes and not in the user-facing supervision article. Apple states the deadline and never states the expiry state.

Microsoft does state part of it, for the Intune case, and it is the sentence quoted two paragraphs above: after the provisional period the remove management option is hidden. That is a first-party statement about the affordance disappearing. What nobody confirms is Apple’s side of it, meaning whether release becomes an Apple Business only operation afterwards. A vendor knowledge base asserts that it does, and that is community-sourced and unconfirmed, so I am not going to print it as fact.

What does exist is indirect first-party evidence that a real boundary is there. Apple’s migration requirements gate device management service migration on the period having passed: a device enrolled manually with Apple Configurator is supported for migration only after the thirty day provisional period, and is explicitly not supported before it. Apple therefore treats “after the provisional period” as a checkable device state that unlocks a capability. That confirms the period ends and that the post-period state differs. It does not tell you what the user loses, and conflating the two would be inventing a fact.

The defensible operational posture, given that: treat the first thirty days after enrolment as a period in which any Configurator-added device may leave your estate without warning, do not use Configurator-added devices for the first cohort of anything that matters, and reconcile the register against your device management service at day thirty-five for every batch. That reconciliation is a one-minute serial paste using the manifest you already have.


The auto-release behaviour, which will catch somebody eventually

Apple documents one more behaviour specific to this path and it is destructive. On devices with iOS 14 and iPadOS 14 or later, where you used Apple Configurator for Mac to enrol the device, removing the device management service enrollment profile causes the device to reset to factory settings and automatically release itself from Apple Business.

Read the scope carefully, because it is narrow in a way that reads like an oversight. Apple names Apple Configurator for Mac specifically. There is no equivalent statement anywhere for devices added with the iPhone app, and Apple neither confirms nor denies that the behaviour differs. The OS floor names iOS and iPadOS only, with no macOS, tvOS or visionOS version given. And the statement appears on the Apple Business and Apple School Manager guide pages but not on the Apple Configurator for Mac page, which is the page about the app the behaviour is scoped to.

Verification gate for later, and put it in your runbook rather than your memory. Before anyone removes a management profile from a device that entered through Configurator, confirm whether that device came in through the Mac app. If it did, removing the profile wipes it and ejects it from the register, and getting it back means running this build sheet again from step 4. Under-documented behaviour that destroys data and inventory records in one action deserves a gate whether or not Apple has drawn its scope carefully.


Completion checklist

Every device in the batch has its serial in a named manifest, written before anything was erased. The right app was used for each device type, checked against the support matrix rather than assumed. Every configured device was erased deliberately, with ownership confirmed and personal Apple Accounts signed out first. Every serial in the manifest returns a device record with a Source of Apple Configurator. Every device is assigned to a device management service and the service can see it. One device has been taken all the way to the remote management pane and through enrolment. The thirty day provisional dates are recorded per batch with a reconciliation booked for day thirty-five. And the runbook now carries the warning about removing enrollment profiles from Mac-app-added devices.

With devices in the register and a way to keep them arriving, the missing piece is the thing they are all waiting to be assigned to. [AB 7] is about the credential that connects Apple Business to Intune, and about why the one everybody worries about is not the one that will hurt them.


Apple Business
‹ Previous: [AB 6.1] Build Sheet: Linking Suppliers and Carriers
Next: [AB 7] The Token That Is Not the One You Think