Managing Macs and iPhones in an Australian business

Apple hardware has quietly become a third of the fleet in a lot of Australian offices, usually without anyone deciding it should. The most consequential management decision is made on the purchase order, months before IT sees the device.

A laptop, phone, earbuds and an external display on a wooden desk, seen from above

"Macs don't get viruses" is not a strategy

The belief that Apple devices look after themselves is doing real damage, because it is half true. macOS does ship meaningful protections by default — Gatekeeper checks that software is signed and notarised, XProtect blocks known malware, System Integrity Protection limits what even an administrator can modify. Compared to an unmanaged Windows machine in 2010, a Mac out of the box is in decent shape.

None of that is device management. Default protections do not tell you whether FileVault is on, whether the OS has been updated this quarter, whether the recovery key is escrowed anywhere you can reach, or what happens when the person holding the laptop resigns. They do not help when the threat is a credential phished out of the user rather than malware dropped on the disk, which is how most compromises now begin. And they stop nothing on the iPhone that has your entire mailbox on it.

Apple Business Manager is the foundation

Apple Business Manager is a free portal, it takes an afternoon to set up, and almost nothing else works properly without it. Three things live there.

  • Automated Device Enrolment. Devices linked to your organisation enrol into your management platform the moment they are switched on and connected, before anyone reaches the desktop. Enrolment is supervised and cannot be removed by wiping the device — which is precisely the property you want on a company asset, and precisely why it has to be established at purchase.
  • Apps and Books. Volume-purchased app licences owned by the organisation rather than by an individual's personal Apple Account. Without this, apps bought for work are tied to a personal account, and you cannot reclaim them when someone leaves.
  • Managed Apple Accounts. Organisation-owned Apple identities, which can be federated with your existing directory so people sign in with their work credentials.

Apple Business Manager is not itself an MDM. It is the trust relationship that lets your MDM — Intune, Jamf, Mosyle, Omnissa, whichever — take control automatically instead of asking nicely.

The decision you make at the purchase order

Here is the part that costs organisations the most and gets the least attention at the time.

For a device to enrol automatically, it generally has to be bought through Apple or through a reseller authorised to add it to your Apple Business Manager account. A MacBook bought from a retail store, or from whichever supplier had stock that week, does not appear in your portal and will not enrol itself. There is a manual path using Apple Configurator, but it requires physically handling the device and comes with a provisional period during which the user can remove the management — which is not the same guarantee at all.

The practical consequence is that where you buy determines whether you can manage the fleet, and the person making that call is often in finance rather than IT, optimising for a discount that is smaller than the cost of manually enrolling every device forever. Give whoever raises the purchase orders one instruction: Apple hardware is bought through the channel linked to our Apple Business Manager, without exception.

Managed Apple Accounts and your directory

Most Australian businesses running Apple devices are also running Microsoft 365, and the two identity systems do not merge on their own. Federating Apple Business Manager with your identity provider means people use their work sign-in for their Managed Apple Account, and suspending the work account suspends the Apple one with it.

Without federation you get a second, parallel set of identities that nobody offboards. It is the same failure as any unmanaged directory: the accounts that matter are the ones nobody remembers exist. If you already have a leavers process, this is one more system it has to reach — better that it reaches automatically.

Where Intune alone starts to strain

If you are a Microsoft 365 organisation, Intune can manage Macs and iPhones and is included in licensing you probably already hold. For a small fleet with modest requirements, that is frequently the right answer and you should not buy a second product to prove a point.

Where it starts to strain is depth. Dedicated Apple management platforms track new macOS and iOS capabilities more closely, tend to expose more granular controls, and generally give better tooling for the Apple-specific problems — managed software updates, complex configuration profiles, patching third-party Mac applications. The question to ask is not which product is better in the abstract. It is: how many Macs do we have, are they in regulated or high-risk roles, and does the gap cost us more than a second platform and the people to run it?

For a dozen Macs in general office roles, Intune. For a design or engineering team living on macOS, or a fleet where Apple is the primary platform, cost the dedicated option properly before dismissing it. The same reasoning applies as in our comparison of Ivanti and Omnissa against Intune: the differences appear at the edges, and whether the edges matter depends entirely on your fleet.

A sensible Mac security baseline

Whatever platform manages them, these are the settings worth enforcing rather than hoping for:

  • FileVault on, with the recovery key escrowed to your management platform. Encryption you cannot recover from is a data loss event waiting for a forgotten password.
  • Managed OS updates with a deadline. Apple ships security fixes quickly and users defer them indefinitely. Set a maximum deferral, not a suggestion.
  • Gatekeeper enforced and not user-overridable, so unsigned software cannot be waved through by whoever is in a hurry.
  • The firewall on, and screen lock enforced — unglamorous, frequently off.
  • Endpoint detection that actually supports macOS properly. Several products technically run on Macs while doing considerably less than they do on Windows. Ask what the difference is rather than assuming parity.
  • A remote lock and wipe you have tested, on a real device, before you need it.

Where to start if none of this exists

The order matters, because each step makes the next one cheaper. Set up Apple Business Manager first — it is free and it unblocks everything. Then fix procurement, so new devices arrive enrollable and the problem stops growing. Then enrol what you can of the existing fleet, accepting that some older devices will need manual handling or will simply be managed from their next refresh. Then apply the baseline, and only then argue about which MDM platform is best.

Organisations reliably do this in reverse — they choose a platform first, then discover none of their existing hardware can be automatically enrolled into it.

Questions

Do we need Jamf, or is Intune enough for our Macs?

For a small Mac fleet in general office roles, Intune is usually enough and is already in your licensing. Dedicated Apple platforms earn their cost where Apple is the primary platform, where you need same-day support for new OS features, or where Mac-specific patching and configuration depth genuinely matter. Count the devices before you count the features.

We bought our Macs from a retail store. Can we still manage them?

Yes, but not automatically. They can be enrolled manually, or added using Apple Configurator, which requires handling each device and gives a weaker guarantee than automated enrolment because the user can remove management during a provisional window. It works. It just does not scale, which is the argument for fixing procurement before buying anything else.

Does managing an iPhone through Apple Business Manager work for BYOD?

Automated enrolment is for devices the organisation owns. For personally owned iPhones you want user enrolment or app-level protection instead, which keeps the personal half of the device out of scope — we covered that choice separately.

Is Apple Business Manager free?

Yes. The portal costs nothing; you pay for the MDM platform that connects to it and for any apps you buy through it. Given that, there is no good reason for an organisation running Apple hardware not to have one set up, even if device management is still six months away.

Apple Business Manager set up properly, once

We will connect the portal, fix the procurement path so new devices arrive enrollable, and enrol what you already own.