Co-managed IT for Mac fleets: How DMS (formerly MDM), Apple Business, and Jamf licensing work when two teams share the fleet

Eight people sit around a table with laptops and notebooks, engaged in a meeting focused on Co Managed IT strategies. One person stands and gestures while speaking about optimising Mac Fleets and managing Jamf Licensing. Large windows provide natural light to the modern office space.

Co-managed IT is often discussed in terms of “people problems,” but the licensing implications are just as critical. When internal IT and an MSP share a Mac fleet, clear ownership of the DMS (Device Management Service) subscription and Apple Business account is essential. Mismanaging this can lead to operational failures when you need emergency access most. This article details the licensing and technical mechanics required to get this right.

Who holds the DMS licence in a co-managed Mac fleet?

The business should hold the primary DMS subscription and the primary Apple Business admin account, not the MSP. If the MSP relationship ends, a business that doesn’t hold its own licence has to renegotiate access to its own device fleet before it can do anything else. The MSP operates within that licence via delegated, admin-level access rather than owning the subscription itself.

How does Apple Business admin access work across two teams?

Apple Business supports exactly this model. The business holds the primary admin account. The MSP is added as a Managed Apple Account with admin-level access, which gives Dr Logic’s team the ability to enrol devices, push configuration, and respond to incidents without needing the internal IT person present for every action. The internal IT person typically also holds a Managed Apple Account at admin level, so both teams can act independently within the same tenant.

Is a Managed Apple Account with admin-level access enough for an MSP, or does the MSP need its own tenant?

For the vast majority of co-managed Mac fleets, a Managed Apple Account with admin-level access inside the business’s own Apple Business tenant is sufficient. A separate MSP tenant adds complexity without a corresponding benefit for most fleet sizes, and it muddies the audit trail that Cyber Essentials assessors want to see: one tenant, with named accounts and clear role assignment, is easier to evidence than access split across two.

What does Jamf or Addigy licensing look like when an MSP and an internal team share a fleet?

The licence itself, whether Jamf or Addigy, should sit under the business’s name, billed either directly or via the MSP as a pass-through cost, but owned by the business. Both platforms support role-based administrator accounts, so the internal IT person and the MSP’s engineers can each have their own login with permissions scoped to what they actually need, rather than sharing a single generic admin credential. Shared logins are the single most common licensing mistake we see in co-managed arrangements: they make it impossible to audit who did what, and they create exactly the kind of access gap a proper responsibility matrix is meant to prevent.

Regardless of the platform chosen, the key is to ensure it is licensed under the business’s name with named, role-scoped logins for each party.

How does the Blueprint model in Apple Business DMS compare to Jamf or Addigy for granular, role-based configuration?

Apple Business DMS uses Blueprints, which are useful for straightforward, fleet-wide configuration but don’t offer the granular, role-based scoping that Jamf’s Smart Groups or Addigy’s policy engine provide. In a co-managed setup where the MSP needs to configure different policy sets for different departments without touching everything at once, Jamf or Addigy’s more granular model is usually the better fit. Apple Business DMS alone can work for smaller, simpler fleets, but as configuration needs diverge across teams, that granularity becomes the deciding factor.

Who owns device enrolment and zero-touch deployment in a co-managed setup?

Enrolment ownership follows the same principle as everything else here: the business’s Apple Business tenant is where devices are registered, and zero-touch deployment is configured against that tenant regardless of which team, internal or MSP, actually carries out the day-to-day enrolment work. The MSP typically handles the practical mechanics of enrolment as part of its scope, but the devices themselves are always tied to the business’s own tenant, not the MSP’s.

What happens to DMS ownership if the internal IT person leaves?

Nothing changes, provided the licensing was set up correctly in the first place. Because the DMS subscription and Apple Business Admin account belong to the business, not to the departing individual, the MSP continues operating exactly as before. The only action needed is revoking the departing employee’s personal Managed Apple Account and, if they held any shared credentials outside the proper role-based structure, rotating those. This is precisely why role-scoped, named logins matter: a departure should be a single account deactivation, not a scramble to work out what that person had access to.

What does a licence transfer look like if a business moves from fully outsourced back to co-managed, or vice versa?

As the licence sits with the business throughout, moving between fully outsourced and co-managed is primarily a change in who does the day-to-day work, not a licence transfer in the technical sense. The DMS subscription and Apple Business tenant stay put. What changes is which named accounts are active and what each party’s role permissions cover.

Who is responsible for cyber essentials evidence collection when licensing is split across two teams?

We’ve set out the full principle in our Responsibility Matrix for Mac-First Businesses guide, so we won’t repeat it here beyond the licensing-specific point: whichever platform generates the compliance evidence, patch logs, device compliance reports, configuration records, that evidence collection should be assigned to one named party in the responsibility matrix, usually the MSP given its familiarity with what an assessor expects, even where the underlying licence belongs to the business.

Getting the licensing model right from day one

The businesses that get this right share a few habits:

  • The DMS subscription and Apple Business Admin account are registered in the business’s name, not the MSP’s.
  • Every party has a named, role-scoped login rather than a shared credential.
  • Enrolment and zero-touch deployment are configured against the business’s own tenant.
  • Evidence collection responsibilities are written into the responsibility matrix, not assumed.
  • Access is reviewed whenever the responsibility matrix itself is reviewed, not left until someone leaves.

If your co-managed arrangement doesn’t already look like this, it’s worth an audit before it becomes a problem rather than after.

DMS and MDM licensing ownership at a glance

FeatureApple Business DMSJamfAddigy
Typical licence holderBusiness (free, built-in)Business, MSP as pass-through billing commonBusiness, MSP as pass-through billing common
Role-based admin accountsLimitedYes, granular via Smart GroupsYes, via policy engine
Compliance / audit evidenceNot generated automaticallyExportable, assessor-readyExportable, assessor-ready
Best fit in co-managed setupsSmall, simple fleetsLarger or more complex fleets needing granular scopingSmaller-to-mid fleets wanting lighter-touch management

Related articles

FAQs

Who should own the Apple Business admin account in a co-managed IT arrangement?

The business should hold the primary Apple Business admin account, not the MSP. The MSP operates through a Managed Apple Account with admin-level access, which lets it manage the fleet fully without owning the underlying tenant or licence.

What happens to device management if our internal IT person leaves?

Nothing changes if licensing was set up correctly, since the DMS subscription and Apple Business account belong to the business. Only the departing employee’s own account needs deactivating, and any shared credentials outside proper role-based access should be rotated.

Should the MSP or the internal IT team hold the Jamf or Addigy licence?

The licence should be registered under the business’s name, even if the MSP handles billing as a pass-through cost. Both the internal IT person and the MSP’s engineers should have their own named, role-scoped login rather than sharing a single admin credential.

Can Apple Business DMS alone support a co-managed Mac fleet without Jamf or Addigy?

For small, simple fleets, yes. Once configuration needs diverge across departments or Cyber Essentials evidencing becomes a priority, Jamf or Addigy’s more granular, role-based configuration and audit-ready reporting usually become necessary.

A man with light brown hair, glasses, and a beard smiles at the camera. He is wearing a black shirt with the logo “DR Logic.” The background shows tall, modern glass buildings.
Shaun

CTO

Shaun is Chief Technology Officer at Dr Logic, overseeing the technical direction of the business and the infrastructure that underpins client environments. He brings hands-on experience across Apple device management, cloud architecture, and enterprise IT strategy, and his articles focus on the technology decisions that help growing businesses scale securely and efficiently.

Explore More Articles

Clear, Actionable Advice – No Jargon, No Pressure.

Get In Touch With an IT Expert

Scaling up, tackling downtime, or reviewing your setup? Contact us or book a quick call for expert advice on running your IT smarter and more securely.

Rather speak to us right now? Our phone number is: 020 3642 6540


Contact Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Book a Consultation Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Want IT to Work Smarter for You?

Get expert tips, security advice, and practical insights for Apple and hybrid teams – straight to your inbox.


Subscription Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.