Apple Business Manager / Apple School Manager
Last Updated: May 2025
Implementation Effort: Medium – Setting up integration with Apple Business Manager (ABM) or Apple School Manager (ASM) requires coordination between Intune and Apple portals, token management, and device assignment workflows.
User Impact: Low – End users are not directly involved in the setup or maintenance; devices are pre-configured before reaching users.
Introduction
Apple Business Manager (ABM) and Apple School Manager (ASM) are Apple’s web-based portals for managing device assignments and enabling Automated Device Enrollment (ADE). Integrating ABM/ASM with Intune is essential for establishing a secure, scalable, and Zero Trust-aligned provisioning process for macOS devices.
This guidance applies to both new deployments and organizations that have already integrated ABM/ASM and want to evaluate their setup through a Zero Trust lens.
Why This Matters
- Enables zero-touch provisioning for corporate macOS devices via ADE.
- Ensures device supervision, which unlocks additional management capabilities.
- Prevents device removal from management, reducing the risk of unmanaged endpoints.
- Supports Zero Trust by enforcing enrollment and configuration at the hardware level.
- Simplifies lifecycle management by automating device assignment and enrollment.
Key Considerations
ABM/ASM Integration with Intune
- Link ABM or ASM to Intune by uploading the MDM server token in the Intune admin center.
- Assign devices to the Intune MDM server in ABM/ASM to enable ADE.
- Renew the MDM server token annually to maintain connectivity.
This integration ensures that only devices acquired through trusted channels are eligible for enrollment, establishing a hardware-rooted trust foundation.
Device Assignment
- Devices purchased through Apple or authorized resellers can be automatically added to ABM/ASM.
- Assign devices to the correct MDM server before they are powered on to ensure zero-touch enrollment.
- Use serial numbers or order numbers to manually add devices if needed.
- For existing environments, audit device assignments to confirm all corporate devices are properly scoped and enrolled.