Apple Business Manager: What Australian Businesses Actually Need to Know

Apple Business, until recently called Apple Business Manager, is Apple’s free web portal for buying, assigning and automatically enrolling company-owned Apple devices, and for issuing staff with work-owned Managed Apple Accounts. If you have Macs or iPhones in the business and you are not using it, you do not own those devices in any administrative sense. You just paid for them.

The name changed on 14 April 2026, and the change is not cosmetic. Apple folded Apple Business Manager, Apple Business Essentials and Apple Business Connect into a single free platform called Apple Business. Existing accounts migrated automatically. If a supplier or a provider is still quoting you on Apple Business Essentials, they have not looked at Apple’s documentation since April.

What Apple Business actually is, and what it is not

It is a directory and an inventory, not a management tool by itself. Historically that was the entire point of confusion. Apple Business holds three things: a record of which devices your organisation owns, a record of which people work for you, and the licences for apps and books you have bought in volume. It then hands those records to a device management service that does the actual configuring.

What is new since April is that Apple now includes a built-in device management service at no cost, using what Apple calls Blueprints and Configurations. This capability was previously the paid, United States only Apple Business Essentials. It is now free and available in Australia. You can use Apple’s built-in service, link an external one such as Intune or Jamf, or run both.

It is free. Apple charges nothing to sign up, nothing per device, and nothing for the built-in device management. The paid components are subscriptions layered on top, and as covered below, most of those are not sold in Australia.

Which features Australia actually gets

Apple publishes a feature availability table by country, and Australia is grouped with India and New Zealand. This is the part most articles written for a United States audience will mislead you on.

Available in Australia:

  • Built-in device management
  • Zero-touch deployment
  • Managed Apple Accounts
  • Get Apps and Get Books, so volume purchasing of both
  • Brand and Location Management, and Branded Mail
  • Tap to Pay on iPhone

Not available in Australia:

  • Mail, Calendar and Directory, Apple’s new business email service
  • Buying AppleCare+ for Business through the portal
  • Buying additional iCloud storage for Managed Apple Accounts
  • Verify with Wallet on the Web

The practical read is good news. Everything that matters for managing a fleet works here. Everything Apple is selling as a subscription on top of it currently does not. Do not build a plan around Apple business email in Australia.

A Managed Apple Account is not a personal Apple Account

A personal Apple Account, which Apple used to call an Apple ID, belongs to the person. A Managed Apple Account belongs to your organisation. You create it, you can reset its password, you control which Apple services it can reach, and when the person leaves you take it back.

The distinction matters most at offboarding. If a designer bought fonts, plug-ins and a decade of App Store software against a personal Apple Account using their work email address, none of that is yours and none of it transfers. If the same purchases were made against volume licences in Apple Business, they are yours, and they can be reassigned.

There is a sting in moving from one to the other. Before Apple will let you federate a domain, you must verify it and then turn on Domain Capture. Apple’s documentation is blunt about what follows: anyone using a personal Apple Account on your domain is notified and given 30 days to transfer their account, the date is fixed and cannot be extended, and turning on Domain Capture cannot be undone. Download the list of unmanaged Apple Accounts on your domain first, tell those people what is about to happen, and give them a path to move personal purchases to a personal address. We have seen this go badly purely because nobody sent the email.

Federation works with Entra ID or Google, but only one at a time

Apple Business can link to Microsoft Entra ID over OpenID Connect, to Google Workspace, or to a generic identity provider using OIDC or SCIM. Staff then sign in to their Managed Apple Account with their existing work credentials, and you can sync users and groups across.

Apple states explicitly that you can link to Google Workspace, Microsoft Entra ID, or your own identity provider, but only one at a time. If you run both Microsoft 365 and Google Workspace, this forces a decision, and it is one of several reasons the identity layer has to be settled before the Apple layer. That argument is set out in full in the guide to running Windows, Mac and Google together.

Two constraints worth knowing before you start. Apple supports the Entra ID global service only, so national clouds are out. And the user principal name in Entra must match the email address, because alternate IDs and UPN aliases are not supported.

Automated Device Enrolment only works if the seller enrols the device

This is the single most commercially important thing in this article, and it turns on how you buy.

Automated Device Enrolment means a Mac or iPhone taken out of its box connects to Apple, discovers it belongs to your organisation, and enrols itself into your management service before the user reaches the desktop. No technician touches it. It can be shipped straight to a home address. Enrolment cannot be skipped or removed by the user.

For that to happen, the device has to be in your Apple Business account, and Apple gives you a limited set of ways to get it there. Buying direct from Apple requires linking your Apple Customer Number. Buying through an Apple Authorised Reseller or an authorised mobile network operator requires exchanging your Organisation ID with them and adding their Reseller Number to your account. Apple then adds a warning that most people miss: once those numbers are exchanged, you still have to arrange for the reseller to submit your orders through their portal, and Apple says it will not happen automatically.

So the failure mode is not exotic. It is a business that has a reseller relationship, has an Apple Business account, and still finds devices are not appearing, because nobody ever told the reseller to submit the orders against the Organisation ID.

The Australian purchasing reality

Australia has a healthy Apple Authorised Reseller channel, and this is where the buying decision bites. A Mac bought over the counter on a company card at a general electronics retailer is a consumer transaction. It is not submitted against your Organisation ID, so it will not appear in Apple Business, and it will not auto-enrol.

Set the account up before the hardware order, not after, and give your reseller the Organisation ID as part of onboarding them. The cost difference on the hardware is usually trivial. The cost difference on twenty devices that have to be manually rebuilt is not. This is one strand of a broader discipline covered in the full Apple device lifecycle and in ordinary IT asset management.

The retail purchase myth, corrected

The common claim is that a Mac bought at retail can never be enrolled. That is not what Apple’s documentation says, and getting this wrong costs businesses money in needless replacements.

You can add retail-bought devices using Apple Configurator, and Apple says so directly, describing it as a way to add devices even when they were not purchased from Apple, an Apple Authorised Reseller or an authorised mobile network operator. For Mac there are specific conditions:

  • It is done with Apple Configurator for iPhone, not the Mac version of the app. You hold an iPhone next to the Mac and scan a pairing image.
  • The Mac must have Apple silicon or an Apple T2 Security Chip, and macOS 12.0.1 or later.
  • It must be sitting at the Select Your Country or Region pane in Setup Assistant. Go past it and you restart.
  • A Mac that has already been set up must be erased first.

Then comes the catch that makes the reseller channel worth insisting on. Apple gives Configurator-added devices a 30-day provisional period, beginning once the device is assigned and enrolled, during which the user can release it from Apple Business, from supervision and from the management service. Devices added through a reseller or bought direct from Apple have no such escape hatch.

For a phone handed to a contractor, thirty days of risk may be acceptable. For a fleet, it is not. Buy properly and the window never exists.

Apps and books are not the same licence

Volume purchasing through Apps and Books is one of the clearest wins in the platform, but the two halves behave differently and people assume they do not.

Apps can be assigned to devices or to users, and Apple confirms you retain full ownership and can revoke and reassign them. Buy fifty licences of a design tool, and when someone leaves, you pull the licence back and give it to their replacement.

Books can only be distributed to users, not devices, and Apple states they cannot be revoked and reassigned. Budget for books as consumed, not as recoverable.

Your App Store locale is set by the address you signed up with, so sign up as an Australian entity and you get the Australian App Store.

What businesses most often get wrong

Treating it as optional because the fleet is small. Ten Macs is enough. The setup takes an afternoon and it is free.

Setting it up after buying the hardware. The account has to exist before the purchase order for auto-enrolment to work.

Confusing it with an MDM. Apple Business now includes a device management service, and for a simple fleet it may be all you need. For anything involving detailed policy, scripting or reporting you will still want a full platform, which is the subject of choosing between Jamf and Intune and the practicalities of managing the Mac fleet itself.

Letting staff enrol their own devices under personal accounts. That is a mobile device management policy question, and it needs answering before the devices arrive rather than after.

Losing the account. Apple Business is a single point of control. If the person who created it leaves without handing over, you have a problem that Apple support cannot always solve quickly. Document it, hold more than one administrator, and treat those credentials like the domain registrar.

Setting up Apple Business properly takes an afternoon, and it is free. The version we would want to walk you through covers domain capture sequencing, reseller onboarding and the identity decision, because those are the three that are painful to reverse. We are a member of the Apple Consultants Network, Apple’s programme of independent technology partners specialising in Apple solutions for small and medium-sized businesses. We deploy and manage Apple fleets through Apple’s business deployment programmes, usually alongside the Windows estate the same business is already running.

If you have Apple devices in the business and no Apple Business account, or one nobody can log in to, call 1300 028 324 or get in touch at https://techassist.au/contact/. We will audit what is already enrolled, what is not, and what it takes to bring the rest in without erasing anyone’s machine.

Jamf Pro and Microsoft Intune both enrol and configure Macs using Apple’s MDM protocol, but Jamf is an Apple-only platform and Intune is one console covering Windows, macOS, iOS and Android. Both are legitimate choices. The comparison is not about which is better in the abstract, it is about how many Macs you have, what you already pay for, and how much control you actually need.

Anyone who tells you one is universally superior is selling something. What follows is what each genuinely does and does not do on macOS as it stands today.

Disclosure before you read any further: we are a Jamf partner and we are also a Microsoft partner, and we run Macs under both products. Being partnered on both sides is what makes this a comparison rather than a pitch, and below you will find the cases where we tell clients not to buy Jamf.

Intune on macOS is far better than its reputation

Intune’s Mac support was thin for years and the reputation has outlasted the reality. It now covers most of what a normal business needs.

Automated Device Enrolment through Apple Business, formerly Apple Business Manager works properly. Compliance policies feed Conditional Access. The settings catalog is now Microsoft’s recommended way to build macOS policy, and it covers both Apple’s declarative configurations such as software update settings and passcode, and traditional payloads such as FileVault, firewall, Gatekeeper and system extensions. Anything Microsoft has not ingested can be uploaded as a custom mobileconfig file. FileVault management with personal recovery key escrow and rotation is supported, as is macOS LAPS for the managed local admin account on Automated Device Enrolment machines. Shell scripts run. App deployment covers volume purchased apps, signed and unsigned packages, disk images and Microsoft’s own applications.

Platform SSO with Microsoft Entra ID is generally available and is genuinely good, particularly the Secure Enclave backed Platform Credential method that Microsoft recommends. It requires macOS 14 or later in practice, the Microsoft Authenticator app, and Company Portal 5.2404.0 or later deployed before you target users.

If you run Microsoft 365 Business Premium, E3 or E5, you already own Intune. For a business with a handful of Macs beside a Windows estate, that is a strong argument on its own.

What Intune genuinely cannot do on macOS

These are the concrete gaps, each of which Microsoft documents.

Endpoint Privilege Management is Windows only. This matters more than anything else on this list. EPM is a headline component of the Intune Suite, and its documentation carries an explicit Windows applicability banner with supported file types of exe, msi and ps1. If you are being sold the Intune Suite as the answer to just-in-time admin rights on Macs, the answer is that it does not do that. Privilege elevation on macOS with Intune means scripting it yourself.

There is no Self Service equivalent. Company Portal can offer apps for a user to install on demand. It cannot publish a policy or a script for a user to run on demand. Jamf Self Service can publish policies, scripts, configuration profiles, apps, patch policies and bookmarks. For a fleet where users need to trigger a printer install, a VPN repair or a re-enrolment themselves, this is the difference between a self-service tile and a support ticket.

There are no policy triggers. Jamf documents six triggers including startup, login, network state change, enrolment complete, recurring check-in and custom events invoked on demand. Intune has no equivalent. Scripts run against the agent’s check-in cycle.

Remediations are Windows only. The detect-and-fix pattern that Windows admins rely on does not exist for macOS in Intune.

Deep device inventory is Windows only. Microsoft’s device inventory feature states that it supports Windows devices only, and that on Apple devices properties are simply collected automatically. You get what the MDM protocol returns and no control over the depth.

Third-party application patching is thin. Enterprise App Management, Microsoft’s automated patching service for non-Microsoft software, is documented as curated Win32 apps. There is no macOS equivalent. Jamf ships both App Installers, where Jamf sources and signs the packages, and classic patch management where you supply the package. Note that App Installers is a Jamf Cloud capability, so it is off the table for on-premises Jamf.

Check-in latency is real. Microsoft documents that newly enrolled Macs check in every 15 minutes for an hour and then roughly every eight hours, with maintenance syncs throttled to one every 6.5 hours. Jamf’s default recurring check-in is every 15 minutes. If you push a policy change on a Friday afternoon, Jamf lands it that afternoon and Intune may not land it until Monday.

Script behaviour is constrained. Microsoft documents scripts under 1 MB, a 60-minute timeout after which the run is marked failed, root execution by default with an option to run as the signed-in user, and an agent check-in every eight hours. Reporting is lossy in a way that trips people up: a recurring script only reports status the first time it runs, and thereafter only when the status changes.

One correction to a common claim: Intune does have an extension attribute analogue in custom attributes for macOS, which run a shell script every eight hours and return a string, integer or date, capped at 20 KB. The real gap is not that they do not exist. It is that they are reporting-only. Jamf extension attributes feed directly into smart group criteria and profile variables. Intune custom attributes cannot be used as dynamic group or filter criteria, so you can see the value but you cannot target on it.

There is more detail in a closer look at Intune on macOS.

What Jamf gives you for the extra licence

Jamf’s advantage is not a longer feature list. It is depth in three specific places.

Smart groups. Jamf evaluates group membership against the entire inventory record, including hardware, operating system, security state, disk encryption, installed applications, package receipts, local user accounts, certificates and your own extension attributes, with nested and-or logic. That is a different order of targeting precision than Entra dynamic groups plus assignment filters.

Self Service and triggers together. Publishing a self-healing action that a user can run on demand, or that fires on login or network change, removes a whole class of support ticket. This is the capability Mac-heavy shops miss most when they move to Intune.

Same-day operating system support. Jamf publishes an annual claim of same-day support for new Apple releases, most recently marking 14 consecutive years. It is a real track record and it matters when a design team updates on release day. Be clear about what it is though: it appears in press releases, not in a service level agreement, with no remedy attached. Treat it as a strong indicator, not a contractual guarantee.

The product line itself is worth getting right, because it changed recently. Jamf’s current plans are Jamf for Mac and Jamf for Mobile, each bundling Jamf Pro with Jamf Connect and Jamf Protect, plus Jamf for K-12 for schools. Jamf Now still exists and has not been discontinued, but it is now positioned for organisations under 25 employees. Jamf Trust is the end-user client app rather than a separate licence.

Licensing structure, and why we are not quoting prices

The two vendors behave completely differently here, and that difference is itself useful information.

Intune is licensed per user and is included in Microsoft 365 E3, E5, F1 and F3, Enterprise Mobility and Security E3 and E5, and Microsoft 365 Business Premium. Above that base sit Intune Plan 2 and the Intune Suite as additive add-ons, along with standalone add-ons such as Remote Help and Endpoint Privilege Management. Microsoft publishes list pricing openly on its Australian pricing page. For most Australian SMBs the marginal cost of managing Macs with Intune is zero, because the licence is already bought.

Jamf publishes no list price for any current plan. Every option is a contact request. The one published figure is a free tier in Jamf Now for up to three devices. Jamf for Mac and Jamf for Mobile are Jamf Cloud only, so on-premises customers are on a different footing. Beyond that, minimum quantities, contract terms and volume tiers are not published, which means the real answer for your fleet size can only come from a quote.

We are not going to print dollar figures here, because Microsoft’s change without notice and Jamf’s are not published at all. What you can rely on is the shape: Intune is usually already paid for, Jamf is always an additional line item, and the question is whether the capability gap justifies it.

Twenty Macs versus two hundred

Around 20 Macs, mostly Windows business, already on Business Premium or E3. Use Intune. Jamf is over-specified at this size and we say so on the call. The licence is sunk, one console is genuinely easier to run, compliance flows into Conditional Access without an integration, and the gaps are survivable at that scale because you can absorb the occasional manual task. Do not buy the Intune Suite expecting privilege management on those Macs.

Around 200 Macs, or Macs as the primary platform. Use Jamf. At that scale the missing self-service, the eight-hour policy latency and the absent third-party patching stop being inconveniences and start being headcount. Smart groups alone will save more time than the licence costs.

The middle, roughly 50 to 100 Macs. This is where it is a genuine judgement call, and the deciding factor is usually the software estate rather than the device count. A team running standard productivity software is fine on Intune. A creative or engineering team with a long tail of third-party applications that all need patching is not, because that is precisely the gap.

If you already pay for Intune, you can run both

This is the option most people do not know exists. Jamf can manage the Macs while Intune owns compliance and Conditional Access, through Microsoft’s partner compliance management integration.

Get the history right, because it changed. The old Conditional Access partner integration is retired. Jamf announced the deprecation with Microsoft and the end of support date was extended to 31 January 2025. The current path is the Device Compliance integration, configured under Device Compliance in Jamf Pro and added as a compliance partner in Intune. Some Microsoft pages still cite the older date, which is a documentation lag rather than a live option.

Practical constraints worth knowing before you commit: the integration supports Entra user groups only, and compliance policies targeted at device groups will not apply. Users must register through Jamf Self Service rather than by launching Company Portal directly. And Jamf-managed devices do not appear in Intune’s device list, so your asset view stays split.

It is more moving parts, and it is the right answer surprisingly often in a genuinely mixed Windows, Mac and Google environment, where the Macs are a meaningful population but the identity and compliance story has to stay in one place.

Our recommendation, and what it costs you

For most Australian SMBs between 10 and 200 staff with fewer than about 50 Macs, start with Intune. You already own it, one console is materially easier to operate and document, and compliance integration is native rather than bolted on.

The trade-off is real and you should accept it knowingly: slower policy delivery, no self-service for users, no on-demand or triggered actions, manual third-party patching, and no privilege management on macOS regardless of which Intune plan you buy. If those constraints start generating tickets rather than mild annoyance, that is your signal to move, and it is a signal that arrives at a fleet size rather than a date.

Whichever you choose, the platform is the smaller half of the problem. Apple’s own rules on supervision, user approval, bootstrap tokens and privacy consent apply identically to both, and they are what actually determine whether your fleet is controlled. That ground is covered in how Mac enrolment and policy actually work and sits alongside your wider approach to endpoint security across the fleet. We run Mac fleets under management alongside Windows, and we are a member of the Apple Consultants Network, Apple’s programme of independent technology partners specialising in Apple solutions for small and medium-sized businesses. That is why this comes out as a fleet-size answer rather than a brand preference.

If you want this decided on evidence rather than a vendor pitch, the useful next step is a short review of your Mac count, your existing Microsoft licensing and the applications those Macs actually run. Call 1300 028 324 or get in touch at https://techassist.au/contact/, and we will give you a straight recommendation, including when the answer is to keep using what you already pay for. We have been doing Mac support in Melbourne for over 20 years.

Ready to Make IT Your
Competitive Advantage?

Book a free consultation with our team. No pressure, no jargon — just a clear-eyed look at where you stand and what's possible.