The Apple Business Deployment Checklist

Everything your organisation needs to get set up right.

Download the full guide.

In April 2026, Apple replaced three separate platforms, Apple Business Manager, Apple Business Essentials, and Apple Business Connect, with a single unified portal: Apple Business. It’s free, available in over 200 countries, and designed to make device management, app distribution, and employee onboarding considerably less complicated.

Whether you’ve been running Apple Business Manager for years or this is all new territory, now is the right moment to get your deployment in order. This guide walks through everything that needs to happen – in the right sequence, with the pitfalls flagged before you hit them.

Use the navigation above to move between sections, or jump straight to the interactive checklist when you’re ready to start ticking things off.

What Actually Changed?

Apple Business Manager was where organisations enrolled devices, managed Apple IDs, and distributed apps. It worked, but it sat alongside two other platforms – Business Essentials and Business Connect – that handled overlapping things in entirely separate places. Apple Business consolidates all of that.

The additions that actually matter:

  • Built-in MDM. Previously, you always needed a separate MDM tool. Apple Business now includes basic device management out of the box via Blueprints – preconfigured templates for settings and apps. For smaller organisations with straightforward needs, this may be sufficient.
  • Proper work/personal data separation. Managed Apple Accounts cryptographically separate work data from personal data on each device. The implementation is now tighter and more deeply integrated.
  • Email, calendar, and directory services. Organisations can set up business email and calendar with a custom domain directly through Apple Business – aimed at smaller organisations not already running Microsoft 365 or Google Workspace.

Identity provider integration. Apple Business integrates with Google Workspace, Microsoft Entra ID, and other services to automatically create Managed Apple Accounts when a new employee is added.

The Prerequisites

This is where most deployments either go smoothly or get stuck for weeks. Get these sorted before you open the Apple Business portal.

D-U-N-S Number

A unique nine-digit identifier for your business, issued by Dun & Bradstreet. Apple uses it to verify your organisation. Many UK businesses already have one – check the Dun & Bradstreet website first. If you need to apply, it’s free, but it may take up to 30 days. Don’t let this hold up your deployment.

Domain Ownership

You’ll need administrative access to your organisation’s email domain to verify your identity and, if you set up identity federation, to automatically link employee accounts.

Verification Contact

Apple contacts a senior person at your organisation, typically your CEO, CFO, or CTO, to confirm the enrolment is legitimate. Brief them in advance. An unexpected call from Apple that goes unanswered can derail the whole process.

Your MDM Decision

Apple Business includes basic MDM through Blueprints. A dedicated third-party MDM (Jamf, Addigy, Mosyle) is the better choice if any of these apply:

  • You manage more than 50 devices
  • You have compliance requirements (e.g. Cyber Essentials, ISO 27001).
  • You need granular device reporting or security posture visibility
  • You manage a mix of Apple and non-Apple devices
  • You want conditional access, patch management, or automated remediation
  • You need remote terminal access or screen sharing without third-party tools
  • You want scripting and custom automation beyond Apple’s policy framework
  • You need PSA integration (ConnectWise, Kaseya, etc.)
  • You want to proactively monitor hardware health, battery state, or disk usage
  • You want integrated EDR or managed detection and response
  • You want BYOD support with clear privacy separation
  • You want alerts and automated remediation when devices drift from a security baseline
  • You want to manage app licences, deployment, and removal centrally across tenants

Your Apple Customer Number

When you buy devices from Apple or an authorised reseller, this number links the purchase to your Apple Business account. Without it, devices won’t appear automatically in the portal for zero-touch enrolment. Make sure your reseller has it before anything ships.

Network Readiness

Devices need to communicate with Apple’s servers during enrolment and ongoing management. If your network has strict firewall rules, Apple domains and ports will need to be whitelisted. Apple publishes the full list in its support documentation.

Phase 1 – Account Setup and Organisation Verification

With the prerequisites handled, the actual sign-up is relatively straightforward.

You’ll create your account at business.apple.com using a company email address – not a personal Apple ID. You’ll enter your business details and D-U-N-S number, then submit for verification.

A few things worth knowing about this stage:

Verification typically takes one to five business days, but it can take longer if Apple can’t reach your verification contact or if there’s a mismatch between your submitted details and what’s on file with Dun & Bradstreet. The most common delay is simply that the verification contact doesn’t pick up the phone.

Your first administrator account must use a real person’s name. Apple rejects entries like “IT Admin” or “Apple Deployment.” This catches people off guard, but it’s a firm requirement.

Set up role-based access from day one. Even if you’re a small organisation, decide now who manages devices, who handles app distribution, and who oversees user accounts. Apple Business supports custom roles, so you’re not limited to a single admin doing everything. It’s much easier to set this up properly at the start than to untangle it later.

Phase 2 – Identity and User Management

This is where you set up how your employees interact with Apple services through work.

Managed Apple Accounts are the foundation. These are work-specific accounts, separate from any personal Apple ID your employees might have. They give the organisation control over business data while keeping personal data private. When someone leaves, you revoke their Managed Apple Account – their personal Apple ID and personal data are untouched.

If your organisation already uses Google Workspace or Microsoft Entra ID (formerly Azure AD), you can connect it to Apple Business to automate account creation. When you add a new employee to your identity provider, their Managed Apple Account is created automatically. When you remove them, access is revoked. This removes a significant manual step from onboarding and offboarding.

If you don’t use one of those identity providers, you can create Managed Apple Accounts manually within Apple Business. It’s more work, but it’s perfectly viable for smaller teams.

Employee groups let you organise people by team, department, or function, and then assign apps, settings, and roles at the group level rather than one by one. Worth setting up early, even if your organisation is small enough that it feels unnecessary right now. It scales with you.

Phase 3 – Device Enrolment

This is where things start to feel tangible. There are two broad scenarios, and most organisations deal with both.

New Devices (Zero-Touch Enrolment)

This is the gold standard and the whole reason Apple Business exists. When you purchase devices from Apple or an authorised reseller and your Apple Customer Number is on the order, those devices automatically appear in your Apple Business portal. You assign them to your MDM – whether that’s Apple’s built-in Blueprints or a third-party tool – and when an employee powers on the device for the first time, it configures itself. Wi-Fi settings, security policies, required apps, and email configuration – all handled before they reach the desktop.

For remote or hybrid teams, this is transformative. You can ship a Mac directly to someone’s home and have it ready to use the moment they open the box. No IT visit required.

Existing Devices

Devices already in use can be enrolled, too, but the process is less seamless. Options include manual enrolment through your MDM or using Apple Configurator (a free Mac app) to add them to your Apple Business account. The level of management control you get may be slightly lower than with zero-touch enrolment, depending on your MDM and how the device was originally set up.

If you’re inheriting a fleet of devices that were set up with personal Apple IDs and no management profile, be realistic: this will involve some manual work and, in some cases, wiping devices. Factor this into your timeline.

The MDM Decision: Built-In vs. Third-Party

Apple Business now includes basic MDM through Blueprints – preconfigured templates for settings, apps, and security policies. For organisations with simple needs and a relatively small fleet (say, under 30 devices, all Apple), this may be enough.

But if any of the following apply, a third-party MDM is likely the better choice:

  • You manage more than about 50 devices
  • You have compliance or regulatory requirements (Cyber Essentials, ISO 27001, etc.)
  • You need granular reporting on device status and security posture
  • You manage a mix of Apple and non-Apple devices
  • You want advanced features like conditional access, patch management, or automated remediation

Phase 4 – App and Content Distribution

Apple Business lets you purchase apps in volume and distribute them to employees without requiring personal Apple IDs. This is cleaner, cheaper, and far easier to manage than the alternative (everyone buying apps individually and expensing them).

A few practical things to know:

You can assign apps to devices or to users. Device-based assignment means the app is tied to the hardware – useful for shared devices or hot-desking setups. User-based assignment follows the person across their devices. Think about which model fits your use case before you start distributing.

Licences are reclaimable. When someone leaves or changes roles, you can revoke their app licence and reassign it. This is easy to forget and easy to waste money on if you don’t build it into your offboarding process.

Custom or in-house apps can be distributed through Apple Business too, which is how most organisations get proprietary tools onto managed devices without going through the public App Store.

Phase 5 – Security and Compliance Baseline

Device management without a security baseline isn’t device management – it’s just an inventory list. Here’s what to put in place from day one.

Passcode and Password Policies

Set minimum requirements for device passcodes. This is basic but often overlooked, especially on iPads and iPhones.

Encryption

On Mac, make sure FileVault is enabled. On iOS and iPadOS, encryption is on by default, but you’ll want to verify it’s not been disabled. Your MDM can enforce this.

Activation Lock Management

Activation Lock prevents anyone from using a device after it’s been wiped without the original Apple ID credentials. With Apple Business, the organisation controls this, which means IT can release Activation Lock on a device that needs to be reassigned or returned. Without it, you end up with expensive paperweights.

Remote Lock and Wipe

 If a device is lost or stolen, you need the ability to lock it immediately and, if necessary, erase it remotely. This should be configured from the start, not set up in a panic after something goes missing.

Wi-Fi and VPN Profiles

Pushing network configuration to devices automatically means employees don’t need to manually enter credentials, and you can ensure they’re connecting securely.

Apple Intelligence Controls

Apple’s on-device AI features are increasingly capable, and some organisations – particularly those in regulated industries – will want to manage which AI features are available on work devices. This is configurable through MDM.

Phase 6 – Ongoing Operations

Deployment isn’t a one-off project. Here’s what the ongoing rhythm looks like.

When Someone Joins

Create their Managed Apple Account (or have it created automatically via your identity provider), assign them to the right employee group, ship or hand over a device that’s already assigned in Apple Business. They power it on, it configures itself, and they start working.

When Someone Leaves

Revoke their Managed Apple Account, reclaim app licences, remotely wipe or reconfigure their device, and release Activation Lock so the device can be reassigned. If you don’t have this process documented, build it now – every organisation has a story about a former employee who still had access to company data months after leaving.

OS Updates

Your MDM can push updates to devices remotely, and you can control the timing,  useful if you want to test updates before rolling them out across the fleet.

Regular Audits

At least once a year, review who has access to what, check that all devices are enrolled and compliant, and update your Blueprints or MDM profiles to reflect any changes in policy or tooling.

Mistakes Worth Avoiding

These come up again and again, and they’re all avoidable.

Buying Devices Before Setting Up Apple Business

Without your Apple Customer Number on the order, those devices can’t be auto-enrolled. You’ll be setting everything up manually, one machine at a time.

Using Personal Apple IDs For Work

 It feels easier in the moment. It creates a mess when someone leaves, company data tangled up in personal accounts, no clean way to separate it.

Ignoring the Verification Request

Apple sends a verification call or email; the CEO doesn’t recognise it and ignores it. The window closes. The account gets deleted. You start again.

Skipping the MDM Decision

Deploying devices without configuring your MDM means there’s no management or security baseline. Retrofitting this onto devices already in use is significantly harder than doing it from the start.

No Offboarding Process

Reclaiming access and devices when someone leaves must be documented and consistently followed, or you risk an ongoing security gap. It’s not a question of whether it causes a problem – only when.

Download the full guide, which includes our Deployment Checklist.

FAQs

What is Apple Business and how is it different from Apple Business Manager?

oIn April 2026, Apple replaced Apple Business Manager, Apple Business Essentials, and Apple Business Connect with a single unified portal called Apple Business. It’s free and available in over 200 countries. The key differences are that Apple Business now includes built-in MDM through Blueprints (previously you always needed a separate MDM tool), tighter work/personal data separation via Managed Apple Accounts, and built-in email, calendar, and directory services for organisations not already running Microsoft 365 or Google Workspace. If your organisation was already using Apple Business Manager, your account transitions into the new platform — but it’s worth reviewing your setup, as the consolidation changes how device management, identity, and app distribution are configured.

What do I need before I can enrol my organisation in Apple Business?

wYou need five things in place before you start. First, a D-U-N-S number — a free nine-digit identifier from Dun & Bradstreet that Apple uses to verify your organisation (allow up to 30 days if you need to apply). Second, administrative access to your company’s email domain for verification and identity federation. Third, a senior contact (CEO, CFO, or CTO) briefed to expect a verification call from Apple — unanswered calls are the most common cause of delays. Fourth, a decision on whether Apple’s built-in MDM (Blueprints) is sufficient or whether you need a third-party MDM like Jamf or Addigy — generally, any organisation with more than 50 devices, compliance requirements, or a mixed Apple/Windows fleet will need the latter. Fifth, your Apple Customer Number linked to your hardware purchases so devices appear automatically for zero-touch enrolment.

How does zero-touch deployment work with Apple Business?

nZero-touch deployment means a new Apple device configures itself automatically the first time an employee turns it on — no IT visit required. When you buy devices from Apple or an authorised reseller with your Apple Customer Number on the order, those devices appear in your Apple Business portal. You assign them to your MDM (either Apple’s built-in Blueprints or a third-party tool), and when the employee powers on the device, Wi-Fi settings, security policies, required apps, and email configuration are all applied before they reach the desktop. This is particularly valuable for remote and hybrid teams because you can ship a Mac directly to someone’s home and have it ready to use the moment they open the box.

Book a Consultation

Book a Consultation Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Clear, Actionable Advice – No Jargon, No Pressure.

Get In Touch With an IT Expert

Scaling up, tackling downtime, or reviewing your setup? Contact us or book a quick call for expert advice on running your IT smarter and more securely.

Rather speak to us right now? Our phone number is: 020 3642 6540


Contact Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Book a Consultation Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Want IT to Work Smarter for You?

Get expert tips, security advice, and practical insights for Apple and hybrid teams – straight to your inbox.


Subscription Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.