Why Most Melbourne MSPs Cannot Support Your Macs Properly

Most Melbourne managed service providers cannot manage a Mac fleet, and most of them will not tell you that during the sales process. They will say Macs are supported, which is true in the sense that someone will answer the phone. It is not the same as managing the device.

This is not a character flaw. It is a structural consequence of how the Australian MSP market was built. Understanding why makes it much easier to ask the two or three questions that expose the gap in about ten minutes.

The market standardised on Windows tooling, and Macs fell out of the stack

An MSP’s economics depend on a single stack: one RMM agent, one patching engine, one antivirus, one documentation system, one ticketing integration. Every one of those products was built for Windows first, and several of them still treat macOS as a checkbox rather than a platform.

The result is a Mac that has an agent installed and nothing else. It appears in the RMM inventory. It reports a serial number and a disk usage figure. It is not enrolled in any device management service, it has no configuration profiles, its FileVault key is nowhere, and nobody has ever pushed a setting to it. On a dashboard it looks green. It is unmanaged.

The second structural problem is people. Windows administration is a well-trodden career path in Australia with a clear certification ladder. macOS at scale is not. Most helpdesks are staffed by technicians who are genuinely competent on Windows and Microsoft 365, have never used a configuration profile, and treat every Mac ticket as a one-off. Escalation goes to whoever owns a Mac personally. That is not a capability, it is a coincidence.

Third, volume. In a typical Australian SMB portfolio Macs are a minority of endpoints, so no MSP builds a practice around them. The finance director, the marketing team and the two designers get the worst service in the business, and because they are a minority they never generate enough noise to change anything.

The tell-tale signs, which you can check yourself

There is no MDM for the Macs at all. Ask which device management service your Macs are enrolled in. If the answer names your RMM product, the answer is none. An RMM agent is not MDM. Apple’s management framework is a separate thing that requires an enrolment profile, and a device that is not enrolled cannot receive configuration profiles, cannot be remotely wiped through Apple’s mechanism, and cannot be supervised.

Devices are not enrolled through Apple Business. Apple replaced Apple Business Manager with a service called Apple Business on 15 April 2026, and Apple’s own footnote on zero-touch deployment states that it “is available when devices are purchased through Apple or Apple Authorised Resellers”. Ask whether your provider has lodged your Organisation ID with your hardware reseller and whether new Macs appear in Apple Business before they are unboxed. Apple publishes a list of Preferred Device Enrolment Resellers for Australia. Your supplier is either on it or you are doing this the hard way.

If the answer is that Macs get set up manually when they arrive, you do not have a deployment process. You have a person.

They cannot patch third-party Mac applications. This is the sharpest question in the list, because the answer is verifiable. Ask how Chrome, Zoom, Adobe or whatever your designers use gets updated on a Mac. There are only three honest answers: a maintained patch feed in an Apple-first MDM, a scripted packaging pipeline the provider maintains, or the applications update themselves and nobody controls it. Intune has no macOS equivalent of its Windows Enterprise App Catalog, so if you are on Intune the answer cannot be “Intune does it”. The detail is in what Intune can and cannot do on macOS.

They do not know what a PPPC profile is. Privacy Preferences Policy Control is Apple’s configuration profile payload that pre-approves specific applications for access to things like the Documents folder, screen recording, Accessibility APIs and full disk access. Its payload identifier is com.apple.TCC.configuration-profile-policy and Apple’s documentation states that “supervision is required if you apply this payload using a device management service”.

Why it matters commercially: without PPPC, your backup client, your EDR agent and your remote support tool all trigger consent dialogs. Users click them away. The agents then quietly fail to do their job and the console still shows them installed. This is the single most common reason a Mac fleet is protected on paper and not in reality. A provider who cannot explain PPPC has not deployed security software to Macs properly, whatever the dashboard says.

Nobody holds the Activation Lock bypass codes. Ask where they are stored. Apple’s documentation is specific: on iPhone and iPad the device-generated bypass code is only retrievable for up to 15 days after the device is first supervised, and “if a device management service doesn’t retrieve the bypass code within 15 days, that bypass code is unretrievable”. If your provider cannot answer this, budget for the day a departing employee leaves a locked MacBook behind.

FileVault keys are not escrowed, or have never been tested. Ask them to retrieve the recovery key for a specific Mac while you watch. Escrow failing silently is common.

No bootstrap token. On an Apple silicon Mac, a bootstrap token escrowed to the management service is required for a remote erase to work. Without it, Apple’s documentation warns the machine can fall back to obliteration, after which macOS must be reinstalled before it can be used. Remote wipe either works or it does not, and you find out on the worst possible day.

Compliance answers stop at the Windows fleet. If you have an Essential Eight target, ask specifically what the maturity position is for the Macs. ASD’s own Maturity Model FAQ defines a workstation as “any device that uses a desktop operating system, such as Microsoft Windows or a Linux distribution”, and its application control file type list is entirely Windows. macOS needs a documented translation and compensating controls, which is the point of the Essential Eight mapped onto macOS. A provider who has not thought about this will tell you the Macs are fine. They are not fine, they are unassessed.

Nine questions to ask your current provider

Send these in an email. Ask for written answers. The quality of the reply tells you more than any capability statement.

  1. Which device management service are our Macs enrolled in, and how many of our Macs are actually enrolled today?
  2. Are our Macs supervised, and were they enrolled through Automated Device Enrolment?
  3. Is our Organisation ID lodged with our hardware reseller, so new Macs appear in Apple Business automatically?
  4. How do third-party applications get patched on our Macs, and where is the report showing current versions?
  5. Do we deploy a PPPC profile, and which applications does it cover?
  6. Where are our Activation Lock bypass codes stored, and can you produce one now?
  7. Can you retrieve the FileVault recovery key for a specific Mac while I watch?
  8. Have bootstrap tokens been escrowed for our Apple silicon Macs?
  9. What is our Essential Eight maturity position for the Mac fleet specifically, and what compensating controls have you documented for application control?

The pattern to watch for: vague answers on 1 to 3, deflection on 4, silence on 5 and 6. A provider who genuinely runs Macs will answer all nine quickly and will probably correct one of your assumptions while doing it.

What good actually looks like

Macs bought through a reseller linked to Apple Business, arriving supervised and enrolled before anyone touches them. Configuration profiles delivering settings rather than a technician clicking through System Settings. A managed local administrator account with a rotating password, and users running as standard. FileVault on with keys escrowed and tested. PPPC deployed so security agents work silently. Software updates enforced through Apple’s declarative device management with a deadline you chose. A named position on third-party application patching, in writing. Activation Lock managed by the organisation, not by whoever signed in first. Offboarding that clears the lock before wiping, in that order.

None of that is exotic. It is the same discipline a competent MSP applies to Windows, applied to a platform whose management model is different rather than harder. It is covered end to end in what proper Mac fleet management looks like and the Apple device lifecycle end to end.

The trade-off is honest and worth naming: doing this properly costs more per Mac than leaving an agent on it. You are paying for a second management platform, or for the internal capability to work around the gaps in the one you have. That is a real decision, and Jamf and Intune compared honestly is where to make it.

Where TechAssist sits

We have been operating for over twenty years, we have thirteen certified specialists, and we run Apple and Mac fleet management as a named service alongside Microsoft 365, Intune, Entra ID and Essential Eight uplift and assessment work. Our head office is in Tecoma in the Dandenong Ranges and we have a Melbourne CBD office, so on-site work in the outer east and across greater Melbourne is us, not a subcontractor.

We are a member of the Apple Consultants Network, Apple’s programme of independent technology partners specialising in Apple solutions for small and medium-sized businesses. We work with Apple’s business deployment programmes for enrolment and device management: Automated Device Enrolment through Apple Business, supervision, configuration profiles including PPPC, FileVault key escrow, bootstrap tokens and Activation Lock held by the organisation. That is the list above, done rather than described.

The reason we can write this post is that we run mixed fleets as a normal state rather than an exception, which is the argument set out in running Windows, Mac and Google in one business. We are also a Microsoft partner, so read the above as an argument about breadth rather than an argument against Microsoft. We are not going to tell you to standardise on Windows because our tooling prefers it.

Send us the nine questions above and we will answer them about your environment, not ours. Call 1300 028 324 or use https://techassist.au/contact/. If your current provider comes out of that well, we will tell you so.

Ready to Make IT Your
Competitive Advantage?

Book a free consultation with our team. No pressure, no jargon — just a clear-eyed look at where you stand and what's possible.