Co-managed IT is often discussed in terms of “people problems,” but the licensing implications are just as critical. When internal IT and an MSP share a Mac fleet, clear ownership of the DMS (Device Management Service) subscription and Apple Business account is essential. Mismanaging this can lead to operational failures when you need emergency access most. This article details the licensing and technical mechanics required to get this right.
Who holds the DMS licence in a co-managed Mac fleet?
The business should hold the primary DMS subscription and the primary Apple Business admin account, not the MSP. If the MSP relationship ends, a business that doesn’t hold its own licence has to renegotiate access to its own device fleet before it can do anything else. The MSP operates within that licence via delegated, admin-level access rather than owning the subscription itself.
How does Apple Business admin access work across two teams?
Apple Business supports exactly this model. The business holds the primary admin account. The MSP is added as a Managed Apple Account with admin-level access, which gives Dr Logic’s team the ability to enrol devices, push configuration, and respond to incidents without needing the internal IT person present for every action. The internal IT person typically also holds a Managed Apple Account at admin level, so both teams can act independently within the same tenant.
Is a Managed Apple Account with admin-level access enough for an MSP, or does the MSP need its own tenant?
For the vast majority of co-managed Mac fleets, a Managed Apple Account with admin-level access inside the business’s own Apple Business tenant is sufficient. A separate MSP tenant adds complexity without a corresponding benefit for most fleet sizes, and it muddies the audit trail that Cyber Essentials assessors want to see: one tenant, with named accounts and clear role assignment, is easier to evidence than access split across two.
What does Jamf or Addigy licensing look like when an MSP and an internal team share a fleet?
The licence itself, whether Jamf or Addigy, should sit under the business’s name, billed either directly or via the MSP as a pass-through cost, but owned by the business. Both platforms support role-based administrator accounts, so the internal IT person and the MSP’s engineers can each have their own login with permissions scoped to what they actually need, rather than sharing a single generic admin credential. Shared logins are the single most common licensing mistake we see in co-managed arrangements: they make it impossible to audit who did what, and they create exactly the kind of access gap a proper responsibility matrix is meant to prevent.
Regardless of the platform chosen, the key is to ensure it is licensed under the business’s name with named, role-scoped logins for each party.
How does the Blueprint model in Apple Business DMS compare to Jamf or Addigy for granular, role-based configuration?
Apple Business DMS uses Blueprints, which are useful for straightforward, fleet-wide configuration but don’t offer the granular, role-based scoping that Jamf’s Smart Groups or Addigy’s policy engine provide. In a co-managed setup where the MSP needs to configure different policy sets for different departments without touching everything at once, Jamf or Addigy’s more granular model is usually the better fit. Apple Business DMS alone can work for smaller, simpler fleets, but as configuration needs diverge across teams, that granularity becomes the deciding factor.
Who owns device enrolment and zero-touch deployment in a co-managed setup?
Enrolment ownership follows the same principle as everything else here: the business’s Apple Business tenant is where devices are registered, and zero-touch deployment is configured against that tenant regardless of which team, internal or MSP, actually carries out the day-to-day enrolment work. The MSP typically handles the practical mechanics of enrolment as part of its scope, but the devices themselves are always tied to the business’s own tenant, not the MSP’s.
What happens to DMS ownership if the internal IT person leaves?
Nothing changes, provided the licensing was set up correctly in the first place. Because the DMS subscription and Apple Business Admin account belong to the business, not to the departing individual, the MSP continues operating exactly as before. The only action needed is revoking the departing employee’s personal Managed Apple Account and, if they held any shared credentials outside the proper role-based structure, rotating those. This is precisely why role-scoped, named logins matter: a departure should be a single account deactivation, not a scramble to work out what that person had access to.
What does a licence transfer look like if a business moves from fully outsourced back to co-managed, or vice versa?
As the licence sits with the business throughout, moving between fully outsourced and co-managed is primarily a change in who does the day-to-day work, not a licence transfer in the technical sense. The DMS subscription and Apple Business tenant stay put. What changes is which named accounts are active and what each party’s role permissions cover.
Who is responsible for cyber essentials evidence collection when licensing is split across two teams?
We’ve set out the full principle in our Responsibility Matrix for Mac-First Businesses guide, so we won’t repeat it here beyond the licensing-specific point: whichever platform generates the compliance evidence, patch logs, device compliance reports, configuration records, that evidence collection should be assigned to one named party in the responsibility matrix, usually the MSP given its familiarity with what an assessor expects, even where the underlying licence belongs to the business.
Getting the licensing model right from day one
The businesses that get this right share a few habits:
- The DMS subscription and Apple Business Admin account are registered in the business’s name, not the MSP’s.
- Every party has a named, role-scoped login rather than a shared credential.
- Enrolment and zero-touch deployment are configured against the business’s own tenant.
- Evidence collection responsibilities are written into the responsibility matrix, not assumed.
- Access is reviewed whenever the responsibility matrix itself is reviewed, not left until someone leaves.
If your co-managed arrangement doesn’t already look like this, it’s worth an audit before it becomes a problem rather than after.
DMS and MDM licensing ownership at a glance
| Feature | Apple Business DMS | Jamf | Addigy |
|---|---|---|---|
| Typical licence holder | Business (free, built-in) | Business, MSP as pass-through billing common | Business, MSP as pass-through billing common |
| Role-based admin accounts | Limited | Yes, granular via Smart Groups | Yes, via policy engine |
| Compliance / audit evidence | Not generated automatically | Exportable, assessor-ready | Exportable, assessor-ready |
| Best fit in co-managed setups | Small, simple fleets | Larger or more complex fleets needing granular scoping | Smaller-to-mid fleets wanting lighter-touch management |
Related articles
- Moving from Fully Outsourced to Co-Managed IT: What the Transition Actually Involves for a Mac-First Business
- Co-Managed IT vs Fully Outsourced IT: Which Model Actually Fits Your Business?
- Do You Still Need a Third-Party DMS (formerly MDM) Now That Apple Business Is Free?
FAQs
Who should own the Apple Business admin account in a co-managed IT arrangement?
The business should hold the primary Apple Business admin account, not the MSP. The MSP operates through a Managed Apple Account with admin-level access, which lets it manage the fleet fully without owning the underlying tenant or licence.
What happens to device management if our internal IT person leaves?
Nothing changes if licensing was set up correctly, since the DMS subscription and Apple Business account belong to the business. Only the departing employee’s own account needs deactivating, and any shared credentials outside proper role-based access should be rotated.
Should the MSP or the internal IT team hold the Jamf or Addigy licence?
The licence should be registered under the business’s name, even if the MSP handles billing as a pass-through cost. Both the internal IT person and the MSP’s engineers should have their own named, role-scoped login rather than sharing a single admin credential.
Can Apple Business DMS alone support a co-managed Mac fleet without Jamf or Addigy?
For small, simple fleets, yes. Once configuration needs diverge across departments or Cyber Essentials evidencing becomes a priority, Jamf or Addigy’s more granular, role-based configuration and audit-ready reporting usually become necessary.



















































