From Enrollment to Deployment: Apple Business and Apple Configurator in Practice

The first whitepaper on this site covered the strategic setup: Apple Business, Microsoft Entra ID, and Intune together. This whitepaper zooms in on the technical, day to day practice: how do you actually get a device from “fresh out of the box” to “fully configured and managed”? We follow the same structure as Apple’s own technical documentation, the Apple Platform Deployment guide, the Apple Business Manager User Guide, the Apple Configurator User Guides, and Apple’s own Platform SSO reference material, moving from implementation model, through enrollment and identity, to declarative management and security. This is an in-depth, technical whitepaper for IT professionals and IT contacts who want to understand the underlying mechanics, not just the end result.

Choosing an implementation model: who owns the device?

Before you get to enrollment, Apple’s documentation first determines who owns the device, since that decides everything that follows. With organization-owned devices, the company buys the devices directly from Apple, an authorized reseller, or a mobile carrier. This can be one to one (each employee gets their own device) or shared, with devices rotating between users. With user-owned devices (BYOD, Bring Your Own Device), the employee buys and configures the device themselves, then enrolls it with the organization’s management service to get access to Wi-Fi, VPN, email, and calendars.

This distinction determines which enrollment method makes sense: organization-owned devices almost always pair with Automated Device Enrollment and mandatory supervision, while BYOD devices typically come in through user enrollment, a lighter form of enrollment (available since iOS 13 / iPadOS 13.1 / macOS 10.15) that stores corporate data in a separate, encrypted APFS volume without supervising the entire device. This keeps a balance between security, privacy, and user experience.

Two paths to enrollment: automatic or through Configurator

The first and most desirable path is Automated Device Enrollment (ADE): buy a Mac, iPhone, or iPad directly from Apple, an authorized reseller, or a participating carrier, and the serial number automatically appears in Apple Business. The moment the device is turned on for the first time, it’s linked to your organization without any intervention, supervised immediately, and assigned to your management service (the built-in MDM in Apple Business, or Intune).

Not every device arrives through those channels, though: second-hand devices, devices that were already in use before a company started with Apple Business, or devices bought outside the official supply chain, have no automatic link. For those cases, there’s a second path: Apple Configurator, a free Mac app that lets you add devices to Apple Business over a cable connection.

What Apple Configurator adds to Apple Business

Connect a device over USB to a Mac running Apple Configurator, and you can add it to your Apple Business account. The device then appears in a separate group called “Apple Configurator” in the Devices overview, after which you can assign it to a management service just like a normal ADE device. From that point on, the device behaves identically to one that arrived through ADE: mandatory supervision and mandatory enrollment with the management service.

Apple Configurator offers two routes here: fully automated setup without anyone needing to touch the screen, or handing the device to the user, who completes Setup Assistant themselves while the link to the organization is already in place.

Blueprints: two concepts with the same name

Both Apple Business and Apple Configurator use the term “Blueprint,” deliberately similar but technically different functionality. An Apple Business Blueprint is a cloud template you link to a role or department; new ADE devices assigned to that role go through the Blueprint automatically, remotely. An Apple Configurator Blueprint works locally: you manually set up one device (apps, profiles, Wi-Fi settings, restrictions, even the wallpaper), record those actions as a Blueprint, and then apply that Blueprint to multiple devices at once over a cable connection.

For IT contacts, this distinction is more than a technicality: a Configurator Blueprint works without a cloud connection and without the device already being in Apple Business, which makes it useful for pilots, quick on-site reconfiguration, or situations where you temporarily have no internet connection.

Supervision: the key to full control

“Supervision” means a device is owned by the organization and IT has extensive control over configuration and restrictions, think of disabling the App Store, enforcing Wi-Fi profiles, or remotely wiping the device. With ADE, supervision is enabled automatically. With Apple Configurator, you can also enable supervision manually on a device connected over cable, which makes Configurator useful for devices managed outside of Apple Business as well.

Identity as the foundation: authentication, authorization, and identity federation

Apple’s own documentation treats identity as a separate, fundamental part of deployment, regardless of which device is involved. Three concepts are central here. Authentication proves who you are (for example with a password or certificate). Authorization then determines what you’re allowed to do, after your username and password have been passed to an identity provider (IdP): the IdP is the “authority,” the credentials form the “assertion,” and what you get back after logging in is the “token.” Identity federation, finally, is the process by which two security domains come to trust each other, so users can move freely between systems without compromising security.

That’s exactly why Apple has made federation possible between Apple Business and both Microsoft Entra ID and Google Workspace: users log in with their existing corporate account for iCloud and on devices linked to the organization, without having to confirm their identity again.

Federation with Microsoft Entra ID: the technical details

Apple Business can connect through federated authentication to Microsoft Entra ID’s global OIDC service (OpenID Connect), reachable via login.microsoftonline.com. Users then log in with their existing Entra ID username (usually their email address) and password as a Managed Apple Account, both on their assigned device and with iCloud on the web.

Once the OIDC connection is broken, the linked accounts automatically turn into standalone accounts, and their attributes can then be managed independently again within Apple Business itself.

Platform SSO for macOS: single sign-on, even before the desktop

Where the Entra ID federation described above handles the account link, Platform SSO (PSSO) handles the actual sign-in experience on the Mac itself, including the moment before the first sign-in on the desktop, during Setup Assistant. Microsoft delivers this functionality through an SSO extension in the Company Portal app for macOS (extension identifier com.microsoft.CompanyPortalMac.ssoextension, configuration profile payload type com.apple.extensiblesso). Similar implementations exist from Okta (through Okta Verify, with a separate macOS download that doesn’t go through the Mac App Store, and for which the “Okta Device Access” feature needs to be enabled separately).

Platform SSO supports three authentication modes, each with its own AuthenticationMethod value in the configuration profile:

Other configurable parameters you’ll come across in practice: LoginFrequency (in seconds, for example 86400 to require a fresh sign-in once every 24 hours), TokenToUserMapping (maps, for example, the Entra ID field preferred_username to the macOS account name), and EnableCreateUserAtLogin (macOS automatically creates a local account at the first PSSO sign-in). For troubleshooting on an already-configured device, the terminal command app-sso platform -s is useful, since it immediately shows the device’s current PSSO registration status and the signed-in user.

Kerberos extension: for local Active Directory, not for Entra ID

A common misconception: the Kerberos SSO extension looks similar to Platform SSO, but is meant for organizations with a local Active Directory domain (Windows Server 2008 or newer), not for Microsoft Entra ID. For Entra ID, you use Platform SSO or the OIDC federation described above; for a traditional on-premises AD domain, you use the Kerberos extension. The two are complementary, not interchangeable, and many SMBs that still have some on-prem AD alongside Entra ID combine both, depending on which device needs to reach which domain.

The Kerberos extension also syncs the local macOS password with the Active Directory password, shows warnings when a password is about to expire, and works with both local and mobile accounts, though password synchronization is only reliable with local accounts.

Managed Apple Accounts and roles

A Managed Apple Account is owned by the organization, not the user, and is fully configured and managed by the organization, separate from any personal Apple accounts. Who is allowed to perform which tasks in Apple Business is determined by a role assigned to each account:

A Managed Apple Account gives access to iCloud collaboration (Keynote, Numbers, Pages, Notes, Reminders), Continuity features, and Shared iPad, but deliberately not to all consumer iCloud features or Store content, keeping business and personal data separate.

Declarative device management: the end of constant polling

Under the hood of modern Apple device management sits declarative device management, an update to the classic MDM protocol that works alongside existing capabilities rather than replacing them. The key difference: instead of the management service constantly having to ask “are you still in the desired state?” (polling), the device itself can proactively report its status the moment something changes, even without an active internet connection, which scales better and uses less network traffic.

A new status channel proactively pushes changes back to the server; the management service can subscribe to specific status items, so a device only reports what’s relevant. For IT contacts, this mainly means newer Apple devices respond faster and more reliably to policy changes than the classic poll-based MDM models much older documentation still assumes.

Device security: flexible, but with sharp edges around BYOD

Apple’s security model is deliberately flexible: passcode policies, configuration profiles, remote wipe, and device management all work together, even when employees use their own devices under a BYOD program. For those BYOD scenarios, user enrollment (available since iOS 13 / iPadOS 13.1 / macOS 10.15 / visionOS 1.1) is the right tool: corporate data lives on a separate, encrypted APFS volume, separated from the user’s personal data, without requiring the entire device to come under full supervision.

When do you choose Apple Configurator alongside Apple Business?

A practical scenario for SMBs

  1. First determine the implementation model: organization-owned (with ADE) or BYOD (with user enrollment), or a combination per department.
  2. Always buy new, organization-owned devices directly from Apple or an authorized reseller, so they automatically appear in ADE in Apple Business.
  3. Have existing or second-hand devices you still want to manage? Add them to Apple Business through Apple Configurator and a cable connection.
  4. Set up federation with Microsoft Entra ID for Managed Apple Accounts, and consider Platform SSO so users can sign in with their Entra ID account as early as Setup Assistant.
  5. Still have a local Active Directory domain alongside Entra ID? Use the Kerberos extension for those Macs, not Platform SSO.
  6. Assign every added device to your management service: the built-in MDM in Apple Business, or Intune when you need conditional access and compliance.
  7. Build Apple Business Blueprints per job function or department, and use Apple Configurator Blueprints locally for pilots or recovery scenarios.
  8. For devices added through Configurator, always communicate the 30-day trial period to the end user.

Preparing for the Apple IT certification path

Apple offers a free, self-paced “Deployment and Management” course through training.apple.com, based on the latest iOS, iPadOS, and macOS versions. Apple states the course takes about 12 hours, though most learners report needing 30 to 60 hours depending on their prior knowledge. Passing the accompanying exam (113 practice questions are available for preparation, and the real exam costs $149) earns the digital badge Apple Certified IT Professional. For IT contacts who want to stand out or formalize their knowledge, this is a low-barrier addition to the practical experience covered in this whitepaper.

This whitepaper is based on Apple’s official documentation (Apple Platform Deployment, the Apple Business Manager User Guide, the Apple Configurator User Guides, and Apple’s Platform SSO reference material) as published in mid-2026. Because Apple, Microsoft, and Okta regularly update this material, we recommend checking the current version on support.apple.com and learn.microsoft.com for the latest details.


Analyst ICT is an officially recognised Apple Technical Partner. Want to know more about Apple within your organisation? See our overview for business or email frank@analystict.nl.

One email. Every last Friday of the month.

The week in Apple, read in three minutes. No rumors, no affiliate filler.

Scroll to Top