Apple Device Lifecycle: Buying, Enrolling, Redeploying and Disposing

The decision that determines how painful the next four years will be is made at the purchase order, not at deployment. Buy Apple hardware through a reseller linked to your Apple Business account and every device enrols itself, stays supervised and can be recovered when an employee leaves. Buy the same machine at retail and you inherit a manual process and, eventually, an Activation Lock problem.

This is the end-to-end lifecycle for an Australian business: procurement, enrolment, assignment, redeployment, the Activation Lock trap, residual value, and what the law actually requires when the device reaches the end of its life.

First, a naming change that matters

Apple replaced Apple Business Manager with a service called Apple Business on 15 April 2026. Apple’s own announcement is explicit: “Apple Business Manager and Apple Business Connect will no longer be available once Apple Business launches”, and Apple Business is “available as a free service” across more than 200 countries and regions. Apple Business is Apple’s free web platform for buying, assigning, enrolling and managing company-owned Apple devices, and it now includes built-in mobile device management alongside the brand and location tools that used to live in Business Connect.

Everything below uses the current naming. If your documentation still says Apple Business Manager, or your provider does, that is a small but useful signal. More on that in Apple’s business device portal.

Procurement: the ABM-linked reseller versus retail decision

Zero-touch deployment only works when Apple knows the device belongs to you. Apple’s own footnote on the Apple Business launch says it plainly: “Zero-touch deployment is available when devices are purchased through Apple or Apple Authorised Resellers.”

How the link works. You exchange three identifiers, and people mix them up constantly:

  • Organisation ID is your unique identifier in Apple Business. You give this to your reseller.
  • Reseller Number identifies the Apple Authorised Reseller or authorised carrier. You add this to your account.
  • Apple Customer Number is the account number Apple assigns your organisation for purchasing. Apple notes this is not the same as your GSX account number, and to omit leading zeros.

The step almost everyone misses is in Apple’s own documentation: after the identifiers are exchanged and verified, you must arrange with the reseller to submit your orders through their portal, because “it won’t happen automatically”. Devices do not appear in Apple Business just because you bought them from a participating reseller. Someone has to lodge the order correctly.

Apple publishes a list of Preferred Device Enrolment Resellers for Australia, which is the right place to check before you commit to a supplier. If your incumbent hardware supplier is not on it and will not lodge your Organisation ID, that is a reason to change supplier, not a reason to change your deployment model.

What retail purchases cost you. Devices bought at an Apple Store, JB Hi-Fi or anywhere else can still be added, using Apple Configurator. Apple Configurator for iPhone can add iPhone, iPad, Apple Vision Pro and Mac (Apple silicon or T2, macOS 12.0.1 or later). Apple Configurator for Mac can add iPhone, iPad and Ethernet-model Apple TV, but cannot add Macs.

The catch is real and worth knowing before you rely on it. Apple’s documentation states that after a device is added this way and handed to a user, “they have a 30-day provisional period to release the device from Apple Business, supervision, and the device management service”. A device supplied through the reseller channel has no such escape hatch. If you are buying at retail to save a few days on lead time, understand that you are also handing every new starter a one-month opt-out from management.

You also have to catch each device at a specific Setup Assistant screen (macOS at “Select Your Country or Region”, iOS and iPadOS at “Choose a Wi-Fi Network”). Miss it and you restart the machine and try again. It is fine for one device. It does not scale.

Enrolment and assignment

Automated Device Enrolment is designed, in Apple’s words, for devices an organisation owns, and “lets organisations configure and manage devices from the moment someone removes a device from its box”. A device enrolled this way is automatically supervised on iOS 13, iPadOS 13.1, macOS 10.14.4 and later.

Supervision is not a bureaucratic nicety. Several controls only work on a supervised device. Apple’s Privacy Preferences Policy Control payload, the one that pre-approves your management agent, security agent and backup client for the access they need, states that “supervision is required if you apply this payload using a device management service”. Without it, every agent you deploy throws consent dialogs that users dismiss, and half your tooling silently does nothing.

The assignment checklist that actually matters:

  1. Device appears in Apple Business with the correct serial number and order.
  2. Device assigned to your device management service before it is unboxed.
  3. Enrolment profile set to mandatory and non-removable.
  4. Managed Apple Account created for the user, so organisational data stays separate from anything personal.
  5. FileVault enabled with the recovery key escrowed and a test retrieval performed.
  6. Bootstrap token escrowed to your management service. On Apple silicon Macs this is required for a remote erase to work later.
  7. Asset record created, linking serial number to person, cost centre and purchase date.

Steps 5, 6 and 7 are the ones skipped under time pressure and the ones you regret. The mechanics sit in enrolment, policy and the bits that break, and the asset side belongs with IT asset management that holds up.

Redeployment when someone leaves

Redeployment is an offboarding problem before it is a hardware problem. The sequence that works:

  1. Disable the user’s directory account and revoke sessions.
  2. Confirm their data is in the tenancy, not only on the device.
  3. Clear Activation Lock before you erase (see below, this order is not negotiable).
  4. Issue a remote erase from your management service.
  5. Verify the device reappears in Apple Business unassigned and clear of Activation Lock.
  6. Reassign to the next user, or route to trade-in or disposal.

If your offboarding process does not include steps 3 and 5, you are building a cupboard full of expensive bricks. This should be wired into your onboarding and offboarding checklist rather than remembered on the day.

Activation Lock: the part businesses get burnt by

Activation Lock ties a device to an Apple Account so it cannot be reactivated without those credentials. Apple now distinguishes two kinds, and the distinction is the whole story.

Organisation-linked Activation Lock requires Apple Business and lets your device management service turn it on and off through server-side interactions. That is the version you want.

User-linked Activation Lock happens when a user signs in with their own personal Apple Account and turns on Find My. Apple’s own device-state table is blunt about the consequences: when user-based Activation Lock is on, it can be turned off in Apple Business, but not through an external device management service.

Three specific traps, all from Apple’s documentation:

The ordering trap. Apple states that “if Activation Lock was already turned on, you won’t be able to turn it off in Apple Business unless the user first turns it off”. If the employee enabled Find My before the device was added to Apple Business, your escape hatch is gone. Add devices to Apple Business first, always.

The bypass code window. On iPhone and iPad the device-generated bypass code is only available for up to 15 days after the device is first supervised. Apple is explicit: “If a device management service doesn’t retrieve the bypass code within 15 days, that bypass code is unretrievable.” Confirm your MDM is actually retrieving and storing these. Confirm it again if you ever change MDM, because Apple warns that on migration you must either receive a copy of the codes or have the outgoing service clear Activation Lock for all enrolled devices.

The macOS 11 trap. For a Mac running macOS 11 or later enrolled via Device Enrolment, Apple notes it “may be possible for Activation Lock to already be turned on when the Mac enrols”, and in that case “you can’t turn it off using a device management service”.

Releasing the device makes it worse, not better. Apple says twice on the same page that “managing Activation Lock using Apple Business isn’t possible after a device is released”, and the interface makes you tick a box confirming you understand the release cannot be undone. Never release a device to try to fix a lock. Also never release a device you are sending to Apple for repair, because if Apple replaces it, the replacement will not appear in your account.

When all else fails, Apple runs an Activation Lock support request process for owners who have proof of purchase documentation. Keep your invoices. This is the entire reason to keep them.

Erasing does not clear the lock. Apple’s guidance is unambiguous: keep Find My on and Activation Lock survives a remote wipe. Clear the lock first, then erase.

Trade-in and residual value

Apple runs Apple Trade In in Australia for both consumer and business customers. Worth knowing how it is structured: Apple’s own terms state that “Apple Trade In is a service provided by Apple’s third-party trade-in vendor”, and the Australian business trade-in runs on a partner platform linked from Apple’s Shop for Business page. It is a real programme; it is not Apple handling your hardware in-house.

Two clauses from Apple’s Australian trade-in terms deserve to be in your process document. First: “You are responsible for backing up and/or deleting data on your trade-in device. Neither Vendor nor Apple will be liable for your data.” Second, the vendor may revise the quoted value if Find My is not removed. Your Activation Lock hygiene has a direct dollar consequence, which is the argument to use when someone asks why offboarding needs to be done properly.

On the buy side, Apple Certified Refurbished in Australia includes a one-year warranty and full functional testing, and AppleCare+ can be added. For non-critical roles it is a legitimate way to lower fleet cost without leaving the managed hardware pool. We do not quote figures here because Apple’s pricing moves and any number in a blog post is out of date within a quarter.

We deliberately publish no dollar amounts for trade-in residual values. Anyone who does is guessing.

Secure erasure: what Apple actually does

On a Mac with Apple silicon or the Apple T2 Security Chip running macOS 12 or later, Erase All Content and Settings performs a cryptographic erase. Apple’s platform security documentation describes the mechanism precisely: volume encryption keys are wrapped with a media key that is “designed to enable swift and secure deletion of data because without it decryption is impossible”, and on these Macs “the media key is guaranteed to be erased by the Secure Enclave supported technology”. Erasing it “renders the volume cryptographically inaccessible”.

Two practical consequences. Disk Utility no longer offers multi-pass secure erase for SSDs at all, and Apple’s advice there is to turn on FileVault instead. And a remote erase on an Apple silicon Mac needs a bootstrap token escrowed to your management service. Without it, Apple’s documentation warns the Mac can fall back to a behaviour called obliteration, after which macOS must be reinstalled before the machine is usable.

Note for anyone quoting ASD: the Information Security Manual’s media guidelines require non-volatile flash memory to be overwritten at least twice with a random pattern and read back for verification, and note that wear levelling means “it is possible that not all memory blocks will be overwritten during sanitisation processes”. The ISM does not address cryptographic erase on self-encrypting devices. Do not claim it endorses the Apple method. Cite Apple for the Apple mechanism and the ISM for the general principle.

Disposal obligations in Australia

Privacy. Australian Privacy Principle 11.2 requires an APP entity that no longer needs personal information, where the information is not a Commonwealth record and is not required to be retained by law, to “take such steps as are reasonable in the circumstances to destroy the information or to ensure that the information is de-identified”. OAIC’s guidelines note that for electronic information it may be possible to sanitise the hardware, and where hardware cannot be sanitised, reasonable steps must be taken to destroy the information another way.

Losing a device that holds personal information can be a data breach. OAIC lists “a device with a customer’s personal information is lost or stolen” as an example. Whether it becomes an eligible data breach turns on likely serious harm and whether remedial action prevented it, which is exactly where a properly escrowed FileVault key and a verified cryptographic erase become the argument you make to the regulator rather than a line item in your incident report.

A certificate of destruction is not a legal requirement in Australia. It is good practice and it is often a contractual requirement. What OAIC actually expects is that you verify and document destruction, including where you have instructed a third party to destroy information. A certificate is the ordinary commercial way to discharge that. OAIC also warns that relying on certification “may not of itself be considered ‘reasonable steps'”. Do not treat the certificate as immunity.

E-waste in Victoria. E-waste has been banned from Victorian landfill since 1 July 2019 and it is illegal to dump it. Business is treated more strictly than households: EPA Victoria states that most e-waste from business and industry is pre-classified as priority waste under Schedule 5 of the Environment Protection Regulations 2021, and that duties under the Environment Protection Act 2017 “apply to the generator, transporter and receiver of e-waste”. You do not discharge your obligation by handing devices to somebody with a ute.

Note that Sustainability Victoria closed on 30 June 2026. If your disposal procedure names it, update the procedure. EPA Victoria is the regulator.

The national scheme. The National Television and Computer Recycling Scheme gives households and small businesses free access to industry-funded collection and recycling for televisions and computers, including printers, computer parts and peripherals. It now sits under the Recycling and Waste Reduction Act 2020, which replaced the Product Stewardship Act 2011 in December 2020. Two limits worth knowing: mobile phones are not covered by the NTCRS, and the scheme is not designed to absorb a corporate fleet refresh. For volume, use a commercial IT asset disposal provider. The detail sits in secure device disposal and e-waste obligations.

Tax. Disposing of a depreciating asset is a balancing adjustment event, and the ATO requires you to compare termination value against adjustable value, with the difference either assessable income or an allowable deduction in the year the event occurs. Note also that if you stop using an asset and never expect to use it again while still holding it, the termination value is the market value at the time you make that decision. Machines shoved in a cupboard are not automatically worthless. Check current thresholds and rules with your accountant or on ato.gov.au rather than trusting a figure in a blog post.

The one-page checklist

At purchase: Organisation ID lodged with the reseller. Order submitted through the reseller portal. Serial numbers confirmed in Apple Business before delivery. Invoice filed and retrievable.

At deployment: Assigned to your management service before unboxing. Supervised. Managed Apple Account issued. FileVault key escrowed and test-retrieved. Bootstrap token escrowed. Activation Lock managed by the organisation, not the user. Asset record created.

At offboarding: Directory account disabled. Data confirmed in the tenancy. Activation Lock cleared. Remote erase issued and verified. Device shown unassigned in Apple Business with Activation Lock cleared. Reassigned, traded or disposed.

At end of life: Cryptographic erase performed and evidenced. Asset tags and markings removed. Licensed disposal or trade-in provider engaged. Destruction verified and documented. Asset register updated. Balancing adjustment recorded.

If most of that list is news to your current provider, that is worth knowing before your next hardware refresh rather than after it, and it is the practical test in whether your provider can actually support Macs.

Bring us your serial number list and we will tell you which devices are in Apple Business, which are Activation Locked to a person who no longer works for you, and what it will take to fix. Call 1300 028 324 or use https://techassist.au/contact/. It is a quicker conversation than most people expect.

Ready to Make IT Your
Competitive Advantage?

Book a free consultation with our team. No pressure, no jargon — just a clear-eyed look at where you stand and what's possible.