Apple Business now includes free MDM: what it does, what it doesn’t, and when your business needs Jamf

A black and white photo showing an Apple iMac, wireless keyboard, iPhone, iPad with Apple Pencil, and AirPods on a desk. Perfect for showcasing Apple Business solutions supported by Jamf Free MDM. The Apple logo is visible on the iMac and iPad.

Apple Business launched in April 2026, consolidating Apple Business Manager and several other Apple platform tools into a single free dashboard, with built-in mobile device management included for every UK business from day one. It is a meaningful addition to Apple’s platform, and it changes the starting point for Mac fleet management.

The question IT leads and business owners are now asking is a practical one: what does Apple Business MDM actually cover, and at what point does a business need to add Jamf on top? The answer depends on your fleet size and compliance posture. This article explains both layers clearly, and gives a direct steer for three common scenarios.

What Apple Business’s built-in MDM actually includes

Apple Business MDM is not a stripped-down product. For small fleets with straightforward requirements, it covers the fundamentals well.

What Blueprints do, and how device assignment works

Blueprints are Apple Business’s way of grouping device configurations into reusable templates. An IT administrator creates a Blueprint that defines which apps are installed, which settings are applied, and which restrictions are enforced, then assigns it to a device or group of devices. Changes to a Blueprint propagate automatically to all assigned devices, no manual intervention required.

This is a meaningful capability. For a growing business deploying Mac, iPhone, and iPad, Blueprints handle the core configuration layer without requiring a dedicated MDM administrator.

Zero-touch deployment: what it means in practice

Zero-touch deployment means a device can be ordered, shipped directly to an employee, powered on, and be fully configured, apps, security policies, user account, without any IT involvement. Apple Business enables this through Automated Device Enrollment, which connects to its built-in MDM layer. When a device hits a Wi-Fi connection for the first time, it recognises the organisation and applies the assigned Blueprint automatically.

For businesses onboarding new starters remotely, this removes a meaningful operational overhead.

The Managed Apple Account structure

Apple Business gives organisations control over Apple IDs at scale. Managed Apple Accounts are created and managed centrally, can be federated with Microsoft Entra ID or Google Workspace, and are deactivated when an employee leaves. This closes a common gap in smaller businesses, where personal Apple IDs are used for work apps and device management becomes impossible when someone departs.

Where Jamf adds capability: what Apple Business MDM doesn’t cover

Apple Business MDM is a solid foundation, but it is designed as a starting layer, not a complete management platform. As fleet size grows and compliance requirements arrive, Jamf is what most businesses add on top. Here is specifically what it brings.

Granular configuration: the depth Jamf adds

Jamf Pro exposes a configuration payload depth that goes well beyond what Apple Business MDM includes. Smart Groups dynamically segment devices based on criteria you define, allowing an IT team to apply targeted policies to subsets of a fleet without touching individual machines. Custom extension attributes, advanced policy scoping, scripted remediation, these are capabilities that make Jamf the right choice for fleets where different teams have different configuration requirements.

Developers with elevated permissions, contractors with restricted access, remote workers with additional VPN policies: Jamf handles this complexity cleanly. Apple Business MDM’s Blueprint model is designed for consistency, not differentiation.

Scripting and automation: where Jamf goes further

Jamf supports shell scripts and automation workflows that run on devices at scale, software installations, configuration checks, and remediation tasks triggered by policy or schedule. This is where IT teams managing mid-sized fleets get significant time back. Apple Business MDM’s built-in layer does not include scripting support, which means anything outside Blueprint-expressible configuration requires a manual touch.

Compliance reporting and audit trails: the critical difference

Jamf generates the kind of exportable, assessor-ready documentation that shows which devices are encrypted, which are running current OS versions, which have enforced password policies, and when each control was last verified. Apple Business MDM does not produce this reporting layer.

In Dr Logic’s experience, the most common gap in Apple-first businesses pursuing Cyber Essentials is not the absence of good security practices, it is the inability to evidence them. A well-managed Apple Business deployment may be doing most of the right things. Jamf is what makes those things provable.

The Cyber Essentials question

For most of Dr Logic’s clients, this is where the decision is made. Cyber Essentials is a procurement requirement, an insurance condition, and increasingly a baseline expectation from clients and suppliers across UK business. The v3.3 standard requires businesses to evidence five technical controls, and “evidence” is the operative word.

What Cyber Essentials requires you to evidence

An assessor does not take your word for it. They want documentation: MDM compliance reports showing patch status across the fleet, screenshots or exports confirming enforced security policies, evidence of MFA enforcement, and confirmation of update management. The standard requires that critical and high-risk patches are applied within 14 days of release, and that you can prove it.

What Apple Business MDM can and cannot produce for an assessor

Apple Business MDM can enforce many of the underlying controls. Devices can be supervised, policies can be applied, apps can be managed centrally. What it cannot do is generate the reports an assessor expects to see. There is no compliance dashboard, no patch status export, no audit log that documents when a control was applied and to which device.

In Dr Logic’s experience, the most common gap in Apple-first businesses pursuing Cyber Essentials is not the absence of good security practices, it is the inability to evidence them. A well-managed Apple Business deployment may be doing most of the right things. But without the reporting layer, you cannot prove it.

What happens at CE+ level

Cyber Essentials Plus involves an independent technical audit, not a self-assessment questionnaire. An auditor will run checks directly against devices in scope. At this level, the requirements for documented, verifiable controls are stricter, and the absence of compliance reporting becomes a hard blocker rather than a friction point. Jamf, configured correctly, produces the evidence trail CE+ requires. Apple Business MDM does not.

The honest decision framework: three scenarios

Scenario 1: Under 25 devices, no Regulatory requirements, early-stage

Apple Business MDM covers the fundamentals well at this scale. Enrolment, zero-touch deployment, basic app management, device supervision, these are in place from day one without additional overhead. For a business at this stage, the right move is to get Apple Business properly configured and treat it as the foundation you will build on. When compliance requirements arrive or the fleet grows, Jamf is the natural next step.

Scenario 2: 25 – 100 devices, Cyber Essentials in scope

You need a third-party MDM alongside Apple Business. The enrolment and deployment layer that Apple Business provides is genuinely useful at this size, but it is not a replacement for the compliance reporting, audit trails, and configuration depth that Cyber Essentials requires you to evidence. Jamf Elevate is designed for exactly this range: 25–250 devices, limited IT resource, compliance requirements that need to be managed without a dedicated MDM administrator.

For the full cost and rollout picture once you’ve hit that threshold, see what a Jamf implementation costs and involves.

Scenario 3: Over 100 devices, ISO 27001 or regulated data

Jamf or an equivalent is non-negotiable. At this scale and compliance level, the requirements for third-party security integrations (CrowdStrike, SentinelOne), CIS Benchmark enforcement, and granular audit reporting are beyond what Apple Business MDM can support. Apple Business remains the right enrolment platform, Jamf sits on top of it and provides the management and compliance layer it does not include.

Running Jamf and Apple Business together: what to expect

Does existing Jamf enrolment survive the Apple Business migration?

Yes. For businesses already using Jamf, the transition to Apple Business had no impact on existing device enrolment or management. Jamf continued to function as before. Apple Business is additive,  it consolidates the enrolment portal and identity layer, but does not replace or conflict with the MDM running on top of it.

Do the two platforms conflict?

No. Jamf is designed to work with Apple’s enrolment and deployment infrastructure, including Apple Business. The two platforms are not competitors at the architectural level, Apple Business handles identity, device registration, and app licensing; Jamf handles the management, policy enforcement, and compliance reporting layer. Businesses that were using Jamf with Apple Business Manager before April 2026 simply migrated to the updated platform, with their Jamf configuration intact.

How Apple Business MDM and Jamf work together

Apple Business and Jamf are not competing platforms, they operate at different layers of the same stack. Apple Business provides the enrolment infrastructure, identity management, and app licensing foundation. Jamf sits on top and adds the management depth, compliance reporting, and security integrations that growing businesses require. The table below shows which layer handles which capability.

CapabilityApple Business MDMJamf (Elevate/Pro)
Zero-Touch DeploymentYesYes (enhanced)
Blueprint / Policy ConfigurationYesYes (advanced, with Smart Groups)
Compliance ReportingFoundation layer onlyFull assessor-ready reporting
Patch Management Audit TrailNot availableYes
Scripting and AutomationNot availableYes
CIS Benchmark EnforcementNot availableYes
Third-Party Security IntegrationsNot availableYes (CrowdStrike, SentinelOne, etc)
Cyber Essentials Evidence GenerationNot availableYes
CE+ Level Audit SupportNot availableYes

Related articles

FAQs

Does Apple Business MDM meet Cyber Essentials requirements?

Apple Business MDM can enforce several of the underlying controls Cyber Essentials requires, but it cannot produce the compliance reports and audit evidence an assessor will expect to see. Most businesses pursuing Cyber Essentials or CE+ certification will need a third-party MDM, such as Jamf, to generate the documentation required to pass.

Can I use Apple Business and Jamf at the same time?

Yes. The two platforms work together and do not conflict. Apple Business handles device enrolment, identity management, and app licensing. Jamf sits on top and provides the management, policy enforcement, and compliance reporting layer. Most well-managed Mac fleets at 25 devices and above use both.

When does a UK business need Jamf rather than Apple Business MDM alone?

The trigger points are fleet size and compliance requirements. For businesses under 25 devices with no regulatory requirements, Apple Business MDM provides a solid foundation and the right starting point. From 25 devices upwards, or as soon as Cyber Essentials comes into scope, Jamf is what adds the compliance reporting, audit trails, and configuration depth that growing businesses need. Dr Logic recommends planning for Jamf early, it is significantly easier to add it before compliance pressure arrives than after.

What to Do Next

If you are unsure whether Apple Business MDM is sufficient for your fleet, Dr Logic can review your current setup and tell you exactly where the gaps are. We work with UK businesses at every stage of Mac fleet maturity, from zero-touch deployment through to full Cyber Essentials certification, and we can tell you whether Jamf is the right next step for your size and compliance requirements.

Speak to our team today.

A man with light brown hair, glasses, and a beard smiles at the camera. He is wearing a black shirt with the logo “DR Logic.” The background shows tall, modern glass buildings.
Shaun

CTO

Shaun is Chief Technology Officer at Dr Logic, overseeing the technical direction of the business and the infrastructure that underpins client environments. He brings hands-on experience across Apple device management, cloud architecture, and enterprise IT strategy, and his articles focus on the technology decisions that help growing businesses scale securely and efficiently.

Explore More Articles

Clear, Actionable Advice – No Jargon, No Pressure.

Get In Touch With an IT Expert

Scaling up, tackling downtime, or reviewing your setup? Contact us or book a quick call for expert advice on running your IT smarter and more securely.

Rather speak to us right now? Our phone number is: 020 3642 6540


Contact Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Book a Consultation Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Want IT to Work Smarter for You?

Get expert tips, security advice, and practical insights for Apple and hybrid teams – straight to your inbox.


Subscription Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.