Guide
Apple Business
Apple Business is the register your Apple estate runs on. It decides which devices your organisation owns, who your people are to Apple, and what software you are entitled to run, and Intune manages what that register permits. Treating it as a mobile device management platform is the mistake that makes Apple deployments go wrong. This guide builds it from a standing start: signing up and verifying an organisation, setting the roles and organisational units that decide who can break what, capturing the domain your Managed Apple Accounts depend on, federating identity with Microsoft Entra ID, getting devices into the register from the channels you actually buy through, and connecting the whole thing to Intune. Then it enrols: the four ways a device can enter, what each one costs you for the life of the hardware, and a single iPhone taken from a sealed box to a device Conditional Access will accept as compliant.
The guide, end to end
16 articles
Apple Business: The System of Record Your Apple Estate Runs On
Apple Business is not your mobile device management platform, and treating it as one is why Apple deployments go wrong. It is the register that decides which devices your organisation owns, who your people are to Apple, and what software you are entitled to run. Intune manages what this register permits.

Getting an Organization: Two Methods, and the D-U-N-S You No Longer Need
Almost everything written about signing up for Apple Business is describing the Apple Developer Program instead, which is why so many organisations believe they need a D-U-N-S number they do not need. Here is what Apple actually asks for in 2026, what the sixty day clock does if you miss it, and who can now enrol who could not before.

Build Sheet: Sign-Up, Verification, and the Organization Profile
By the end of this you have a verified Apple Business organization, two Organization Administrators, a verified domain, your purchase history visible, and your Organization ID recorded, with every irreversible step gated by a check that runs before it rather than after.

Roles, Organizational Units, and Who Can Break What
Apple Business has a permission model that looks like a formality and is not. Ten people can hold the top role and no more, the role that configures single sign-on cannot use it, and a connected management platform may arrive holding the ability to release your devices without anybody signing in.

Managed Apple Accounts, and the Domain You Are About to Capture
Verifying your domain in Apple Business gives you the power to take over every personal Apple account your employees created on it. Apple will not tell you who they are, the clock is thirty days and cannot be extended, and the step cannot be undone. This is what that authority actually costs.

Build Sheet: Locking and Capturing a Domain
By the end of this you have a locked domain, a defensible list of the people Apple is about to email, a communication that went out before Apple's did, a live roster for the thirty day window, and a capture you started deliberately. Apple will not give you the list. Your mail platform will.

Federating Apple Business with Microsoft Entra ID
Federation makes Entra ID the authority for who your people are on Apple hardware, and Apple reads from it without ever writing back. It also renames existing accounts silently, excludes the administrators who configure it, and refuses to work at all while a single domain conflict remains.

Build Sheet: Federation and Directory Sync, End to End
By the end of this your people sign in to Apple devices with their Entra ID credential, their accounts arrive from your directory without anyone typing them, and the Global Administrator grant you needed to build it has been handed back. Every irreversible step has a check in front of it.

How Devices Enter: Customer Numbers, Reseller Numbers, and the Carrier Channel
Apple Business does not record that you own a device. It records that somebody sold it to you, and the record is written by the seller rather than by you. Everything downstream of that, zero touch included, rests on a claim you did not make and cannot make yourself.

Build Sheet: Linking Suppliers and Carriers
By the end of this you have your Organization ID in the hands of every supplier who sells you Apple hardware, their Reseller Numbers in your tenant, a durable record of which opaque number belongs to whom, a monitored feed of Apple's five order progress messages, and a single test device that proves the whole chain works before you order two hundred.

Build Sheet: Adding Owned Devices with Apple Configurator
Devices that never came through a channel can still enter Apple Business, on a claim you make in physical possession of the hardware. Apple hedges that claim with a thirty day window in which the user can walk the device back out, and never says what happens on day thirty-one, though Microsoft says part of it. Here is the whole path, including the platform split that sends you to the wrong app.

The Token That Is Not the One You Think
Two credentials connect Apple to Intune and most organisations guard the wrong one. One of them is bound to a person's password, expires on a clock nobody displays on the authoritative side, and can be destroyed in a single click from a menu Apple hid behind an ellipsis.

Build Sheet: Connecting Apple Business to Intune
Two files cross between two vendors' portals in one browser session, one of them is a credential that is invalidated if you close a tab, and the screen where you grant a piece of destructive authority is one neither vendor documents properly. Here is the whole connection, the recovery route when it goes wrong, and a renewal procedure you can actually keep.

Four Ways In, and What Each One Costs You
Every Apple device in your estate arrives through one of four doors, and the door decides what you are allowed to do with the device for the rest of its life. Here is what each one buys, what each one forecloses permanently, and the one Apple built that Intune has not opened.

Zero Touch: Enrollment Policies and the Authentication Decision
An Apple enrollment policy is read by the device once, during activation, and never again, which makes it the only object in this stack whose half-life is the hardware refresh cycle. Inside it sits an authentication choice that decides whether your fleet is governed or merely managed, and a first-party limitation that contradicts what every Zero Trust article on this site tells you to do.

Build Sheet: A Zero-Touch iPhone, Box to Conditional Access
One iPhone, still sealed, to a device that Conditional Access will accept as compliant, with nobody touching it but the person it belongs to. Every setting, why it is set that way, the two decisions you cannot revisit without a wipe, and the state you should see at each of eight checkpoints.



