diff --git a/articles/6-business-benefits-of-apple-mdm-explained.md b/articles/6-business-benefits-of-apple-mdm-explained.md index 7093d370e6d..46dbcd75964 100644 --- a/articles/6-business-benefits-of-apple-mdm-explained.md +++ b/articles/6-business-benefits-of-apple-mdm-explained.md @@ -1,6 +1,6 @@ # 6 business benefits of Apple MDM, explained -The Apple [Mobile Device Management](https://support.apple.com/guide/deployment/intro-to-apple-platform-deployment-dep2c1b2a43a/web) (MDM) protocol provides remote management capabilities organizations need to configure and secure Apple devices like Macs, iPhones, iPads, Apple TV and even Apple Watch. Combined with Apple Business Manager or Apple School Manager (ABM / ASM) organizations can achieve scalable zero-touch enrollment, automated provisioning and comprehensive security enforcement resulting in fast, simplified device deployment across distributed workforces. +The Apple [Mobile Device Management](https://support.apple.com/guide/deployment/intro-to-apple-platform-deployment-dep2c1b2a43a/web) (MDM) protocol provides remote management capabilities organizations need to configure and secure Apple devices like Macs, iPhones, iPads, Apple TV and even Apple Watch. Combined with Apple Business or Apple School Manager (AB / ASM) organizations can achieve scalable zero-touch enrollment, automated provisioning and comprehensive security enforcement resulting in fast, simplified device deployment across distributed workforces. ## What is Apple Mobile Device Management (MDM)? @@ -117,7 +117,7 @@ Employees think about their work rather than fighting with the device that been ## Getting started with Apple MDM -[Fleet](https://fleetdm.com/device-management) provides enterprise-grade MDM with API-first architecture, real-time device reporting, and cross-platform support for Mac, Windows, and Linux. It also integrates with Apple Business Manager for zero-touch deployment while maintaining complete data transparency. [Schedule a demo](https://fleetdm.com/contact) to see how open device management works without vendor lock-in. +[Fleet](https://fleetdm.com/device-management) provides enterprise-grade MDM with API-first architecture, real-time device reporting, and cross-platform support for Mac, Windows, and Linux. It also integrates with Apple Business for zero-touch deployment while maintaining complete data transparency. [Schedule a demo](https://fleetdm.com/contact) to see how open device management works without vendor lock-in. diff --git a/articles/apple-device-enrollment-program.md b/articles/apple-device-enrollment-program.md index bcbf0b0847f..1fedd98e563 100644 --- a/articles/apple-device-enrollment-program.md +++ b/articles/apple-device-enrollment-program.md @@ -6,7 +6,7 @@ This article covers how ADE works, which devices qualify, security controls, and ## Automated Device Enrollment overview -ADE links devices purchased through authorized channels to your organization in Apple Business Manager (ABM) before they reach employees, allowing them to ship directly to end users. When users power on their devices for the first time and connect to the internet, automatic MDM enrollment begins. Users complete Setup Assistant screens while device configuration applies from your [MDM server](https://fleetdm.com/device-management) in the background. +ADE links devices purchased through authorized channels to your organization in Apple Business (AB) before they reach employees, allowing them to ship directly to end users. When users power on their devices for the first time and connect to the internet, automatic MDM enrollment begins. Users complete Setup Assistant screens while device configuration applies from your [MDM server](https://fleetdm.com/device-management) in the background. Apple originally launched this capability in 2014 as the Device Enrollment Program and rebranded it to Automated Device Enrollment (ADE) in December 2019 alongside the launch of ABM. The underlying technology remained the same, but the new name better describes what the system actually does. @@ -79,7 +79,7 @@ ADE is an enrollment mechanism configured through ABM, not a complete management When evaluating MDM vendors for ADE compatibility, you need to verify several technical requirements. Check that the platform supports Apple Push Notification certificate management with annual renewal processes, offers Setup Assistant customization options that let you control the enrollment experience, and can handle multiple MDM servers if your organization needs different management systems for different regions or business units. -When migrating from one management service to another, if your devices are on older versions of Apple operating systems they may need to be completely erased to re-enroll. If possible, admins should ensure all devices are on the latest Apple OS version. [Managed Device Migration](https://support.apple.com/guide/deployment/migrate-managed-devices-dep4acb2aa44/web) announced at [WWDC 2025](https://fleetdm.com/announcements/mdm-just-got-better) allows computers and mobile devices to be migrated without erasing simply by moving device records from one virtual MDM server to another in Apple Business manager. Limited tests of migration behavior on test devices before comitting to your entire fleet will determine if OS updates are needed. +When migrating from one management service to another, if your devices are on older versions of Apple operating systems they may need to be completely erased to re-enroll. If possible, admins should ensure all devices are on the latest Apple OS version. [Managed Device Migration](https://support.apple.com/guide/deployment/migrate-managed-devices-dep4acb2aa44/web) announced at [WWDC 2025](https://fleetdm.com/announcements/mdm-just-got-better) allows computers and mobile devices to be migrated without erasing simply by moving device records from one virtual MDM server to another in Apple Business. Limited tests of migration behavior on test devices before comitting to your entire fleet will determine if OS updates are needed. Cross-platform capabilities also matter if you manage more than just Apple devices. Organizations with mixed device environments benefit from MDM platforms that handle Mac, Windows, and [Linux](https://fleetdm.com/guides/how-to-install-osquery-and-enroll-linux-devices-into-fleet) from a single console rather than juggling separate management tools. [Fleet](http://fleetdm.com) supports ADE enrollment for Mac, iPhone, and iPad devices while also managing Windows and Linux endpoints. Its open-source model provides complete code transparency so you can verify exactly how devices are managed, and self-hosting options let you maintain full control over where device data lives. @@ -89,13 +89,13 @@ Setting up ADE requires some upfront preparation to ensure smooth deployment. Yo You should start by confirming you have these essential prerequisites in place: -* Apple Business Manager account with D-U-N-S number and domain verification +* Apple Business account with D-U-N-S number and domain verification * [MDM vendor](http://fleetdm.com) supporting ADE enrollment and APNs certificate management * Authorized reseller relationships for automatic device registration * Network infrastructure permitting connections to Apple servers without SSL/TLS inspection * Certificate renewal procedures using the same Apple ID for annual APNs renewal -Beyond technical infrastructure, configuration planning determines how users experience enrollment. You need to define enrollment profiles that specify which Setup Assistant screens users see during initial setup, establish device naming conventions that make sense for your IT team, and create department-specific configurations for different user groups. Make sure to assign these profiles in Apple Business Manager before distributing devices so enrollment happens smoothly without last-minute troubleshooting. +Beyond technical infrastructure, configuration planning determines how users experience enrollment. You need to define enrollment profiles that specify which Setup Assistant screens users see during initial setup, establish device naming conventions that make sense for your IT team, and create department-specific configurations for different user groups. Make sure to assign these profiles in Apple Business before distributing devices so enrollment happens smoothly without last-minute troubleshooting. ## Conclusion diff --git a/articles/apple-mdm-setup.md b/articles/apple-mdm-setup.md index 7a5be252936..a645e41eef8 100644 --- a/articles/apple-mdm-setup.md +++ b/articles/apple-mdm-setup.md @@ -2,7 +2,7 @@ To turn on macOS, iOS, and iPadOS MDM features, follow the instructions on this page to connect Fleet to Apple Push Notification service (APNs). -To use automatic enrollment (aka zero-touch) features on macOS, iOS, and iPadOS, follow instructions to connect Fleet with Apple Business Manager (ABM). +To use automatic enrollment (aka zero-touch) features on macOS, iOS, and iPadOS, follow instructions to connect Fleet with Apple Business (AB). To turn on Windows MDM features, head to this [Windows MDM setup article](https://fleetdm.com/guides/windows-mdm-setup). @@ -19,7 +19,7 @@ Then select **Turn on** under the Apple (macOS, iOS, iPadOS) MDM section. > - If your certificate expires, you must turn MDM off and back on for all macOS hosts. Until then, configuration profile changes and other MDM commands will remain stuck in “Pending.” > - Be sure to use the same Apple ID from year-to-year. If you don't, you will have to turn MDM off and back on for all macOS hosts. -## Apple Business Manager (ABM) +## Apple Business (AB) > Available in Fleet Premium @@ -35,11 +35,11 @@ When one of your uploaded ABM tokens has expired or is within 30 days of expirin To renew an ABM token: 1. Navigate to the **Settings > Integrations > Mobile device management (MDM)** page. -2. Under **Automatic enrollment**, select **Edit**, and then find the token that you want to renew. Token status is indicated in the **Renew date** column: tokens less than 30 days from expiring will have a yellow indicator, and expired tokens will have a red indicator. Select the **Actions** dropdown for the token and then select **Renew**. Follow the instructions in the modal to download a new token from Apple Business Manager and then upload the new token to Fleet. +2. Under **Automatic enrollment**, select **Edit**, and then find the token that you want to renew. Token status is indicated in the **Renew date** column: tokens less than 30 days from expiring will have a yellow indicator, and expired tokens will have a red indicator. Select the **Actions** dropdown for the token and then select **Renew**. Follow the instructions in the modal to download a new token from Apple Business and then upload the new token to Fleet. After connecting Fleet to ABM, set Fleet to be the MDM for all Macs: -1. Log in to [Apple Business Manager](https://business.apple.com) +1. Log in to [Apple Business](https://business.apple.com) 2. Select your profile icon in the bottom left 3. Select **Preferences** 4. Select **MDM Server Assignment** and select **Edit** next to **Default Server Assignment**. @@ -64,7 +64,7 @@ Fleet supports manually turning on MDM for macOS hosts that are already enrolled End users can turn on MDM from their **Fleet Desktop > My device** page. -### Host is in Apple Business Manager (ABM) +### Host is in Apple Business (AB) If a macOS host is listed in ABM: @@ -89,7 +89,7 @@ Connect Fleet to VPP to deploy [Apple App Store apps](https://fleetdm.com/guides 1. In Fleet, select your avatar on the far right of the main navigation menu, and then **Settings > Integrations > Mobile device management (MDM)** -2. In the **Volume Purchasing Program (VPP)** section, select **Add VPP**, and then select **Add VPP** again on the following page. Follow the directions on the modal to get your VPP token from Apple Business Manager, and then select the **Upload** button at the bottom to upload it to Fleet. +2. In the **Volume Purchasing Program (VPP)** section, select **Add VPP**, and then select **Add VPP** again on the following page. Follow the directions on the modal to get your VPP token from Apple Business, and then select the **Upload** button at the bottom to upload it to Fleet. 3. To assign the VPP token to a specific fleet, find the token in the table of VPP tokens. Select the **Actions** dropdown, and then select **Edit fleets**. Use the picker to select which fleet(s) this VPP token should be assigned to. @@ -97,7 +97,7 @@ To renew a VPP token: 1. Navigate to the **Settings > Integrations > Mobile device management (MDM)** page -2. Under **Volume Purchasing Program (VPP)**, select **Edit** and then find the token that you want to renew. Token status is indicated in the **Renew date** column: tokens less than 30 days from expiring will have a yellow indicator, and expired tokens will have a red indicator. Select the **Actions** dropdown for the token and then select **Renew**. Follow the instructions in the modal to download a new token from Apple Business Manager and then upload the new token to Fleet. +2. Under **Volume Purchasing Program (VPP)**, select **Edit** and then find the token that you want to renew. Token status is indicated in the **Renew date** column: tokens less than 30 days from expiring will have a yellow indicator, and expired tokens will have a red indicator. Select the **Actions** dropdown for the token and then select **Renew**. Follow the instructions in the modal to download a new token from Apple Business and then upload the new token to Fleet. ## Best practice diff --git a/articles/apple-push-notification-service-apns-mdm.md b/articles/apple-push-notification-service-apns-mdm.md index 98cd6f0482a..677a3a30ed9 100644 --- a/articles/apple-push-notification-service-apns-mdm.md +++ b/articles/apple-push-notification-service-apns-mdm.md @@ -14,8 +14,8 @@ If you're managing Apple devices, APNs isn't optional. Most of what you do on-de The following MDM functions depend on APNs communication: -* Apps and Books management: Installations, updates, and removals from Apple Business Manager typically flow through the APNs-triggered check-in process. -* Automated Device Enrollment: After a new device activates and enrolls through Apple Business Manager, ongoing on-demand management depends on APNs. +* Apps and Books management: Installations, updates, and removals from Apple Business typically flow through the APNs-triggered check-in process. +* Automated Device Enrollment: After a new device activates and enrolls through Apple Business, ongoing on-demand management depends on APNs. * Configuration profiles: New security settings, VPN settings, and restrictions need an APNs notification to trigger the check-in that downloads them. * MDM commands: Lock, wipe, and restart actions only reach devices after APNs delivers the wake-up signal. If that path is blocked, these commands can sit in the queue with no visible error in your console. * OS updates: Pushing operating system updates to managed devices uses the same APNs channel to prompt check-ins. @@ -78,7 +78,7 @@ The certificate lifecycle and network requirements above apply regardless of whi Fleet handles APNs certificate configuration as part of its [MDM setup](https://fleetdm.com/guides/macos-mdm-setup) process, covering certificate generation, upload, and renewal tracking for macOS, iOS, and iPadOS devices. Fleet also encrypts APNs-related configuration values and outlines renewal procedures within its guides. -Fleet integrates with Apple Business Manager for Automated Device Enrollment and can support multiple Apple Business Manager tokens within a single Fleet instance for managed service providers and larger enterprises. +Fleet integrates with Apple Business for Automated Device Enrollment and can support multiple Apple Business tokens within a single Fleet instance for managed service providers and larger enterprises. Fleet has many options for migration from your current device management service. Fleet is fully compatible with Apple’s [Managed Device Migration](https://support.apple.com/guide/deployment/migrate-managed-devices-dep4acb2aa44/web) features and has its own [end user enabled migration workflow](https://fleetdm.com/guides/mdm-migration#end-user-workflow) built in. Fleet also supports [MDM migration](https://fleetdm.com/guides/seamless-mdm-migration) workflows that can preserve APNs and SCEP certificates. Certificate-preserving migration is not the preferred migration option for most customers. In supported scenarios, migration involves copying certificates from the existing server and retaining the same ServerURL, CheckinURL, and PushTopic values so devices typically don't need to re-enroll. In practice, this process often involves database configuration changes and load balancer redirects. Fleet's Customer Success team must assist with certificate-preserving migrations that require database manipulation for both cloud and self-hosted instances. diff --git a/articles/automated-provisioning-for-Linux-desktop-in-the-enterprise.md b/articles/automated-provisioning-for-Linux-desktop-in-the-enterprise.md index 0686f4a55b1..87c60602eeb 100644 --- a/articles/automated-provisioning-for-Linux-desktop-in-the-enterprise.md +++ b/articles/automated-provisioning-for-Linux-desktop-in-the-enterprise.md @@ -57,7 +57,7 @@ Third, automated device provisioning establishes the connection between **end us ## Best practices for automated provisioning on Linux deployments -If your organization is purchasing computers directly from a large manufacturer like Dell or Lenovo, or from a 3rd party reseller like CDW or SHI, they all offer computers preinstalled with Linux. This is often the simplest and best way to start with enterprise Linux deployments. There is no MDM specification / protocol for Linux and there is no central registry for Linux computers like [Apple Business Manager (ABM)](https://support.apple.com/guide/apple-business-manager/sign-up-axm402206497/web) or [Microsoft Entra](https://learn.microsoft.com/en-us/entra/fundamentals/what-is-entra). +If your organization is purchasing computers directly from a large manufacturer like Dell or Lenovo, or from a 3rd party reseller like CDW or SHI, they all offer computers preinstalled with Linux. This is often the simplest and best way to start with enterprise Linux deployments. There is no MDM specification / protocol for Linux and there is no central registry for Linux computers like [Apple Business (AB)](https://support.apple.com/guide/apple-business-manager/sign-up-axm402206497/web) or [Microsoft Entra](https://learn.microsoft.com/en-us/entra/fundamentals/what-is-entra). Typically, orchestration approaches are used for managing Linux devices at scale. diff --git a/articles/automatic-software-install-in-fleet.md b/articles/automatic-software-install-in-fleet.md index ebf429321ca..e32c1886cc3 100644 --- a/articles/automatic-software-install-in-fleet.md +++ b/articles/automatic-software-install-in-fleet.md @@ -46,7 +46,7 @@ If the software install fails, you can reset a software automation and trigger t ![Flowchart](../website/assets/images/articles/automatic-software-install-workflow-674x189@2x.png) *Detailed flowchart* -App Store (VPP) apps won't be installed if a host has MDM turned off or if you run out of licenses (purchased in Apple Business Manager). Currently, these errors aren't surfaced in Fleet. After turning MDM on for a host or purchasing more licenses, you can retry [installing the app on the host's **Host details** page](https://fleetdm.com/guides/deploy-software-packages#install-the-package). To retry on multiple hosts at once, head to **Policies > Manage Automations** in Fleet and turn the app's policy automation off and back on. +App Store (VPP) apps won't be installed if a host has MDM turned off or if you run out of licenses (purchased in Apple Business). Currently, these errors aren't surfaced in Fleet. After turning MDM on for a host or purchasing more licenses, you can retry [installing the app on the host's **Host details** page](https://fleetdm.com/guides/deploy-software-packages#install-the-package). To retry on multiple hosts at once, head to **Policies > Manage Automations** in Fleet and turn the app's policy automation off and back on. Uninstalling VPP apps is [coming soon](https://github.com/fleetdm/fleet/issues/25497). diff --git a/articles/debunk-the-cross-platform-myth.md b/articles/debunk-the-cross-platform-myth.md index fee078a0c2f..17d99c2a76a 100644 --- a/articles/debunk-the-cross-platform-myth.md +++ b/articles/debunk-the-cross-platform-myth.md @@ -16,7 +16,7 @@ By working directly with native operating system features, Fleet ensures you don For example: * **Operating systems**: You can enforce OS updates with Declarative Device Management (DDM), Nudge, and Windows Update from one console. -* **Automated enrollment**: Drop-ship devices to your end users with Apple Business Manager or Autopilot and let them set up their own accounts. No IT help is needed. +* **Automated enrollment**: Drop-ship devices to your end users with Apple Business or Autopilot and let them set up their own accounts. No IT help is needed. * **Config management**: Manage settings with configuration profiles for Apple and device profiles for Windows. Use labels to test changes before they go live. * **App management**: Automatically keep applications and plugins secure and up-to-date. Install the software end users need or let them install it themselves via self-service. * **Scripts and events**: Easily manage and version control your custom script library. Execute shell and PowerShell scripts when computers drift from the baseline. diff --git a/articles/end-user-authentication.md b/articles/end-user-authentication.md index 155ccef37b2..5c9c181a31d 100644 --- a/articles/end-user-authentication.md +++ b/articles/end-user-authentication.md @@ -6,17 +6,17 @@ Fleet MDM server simplifies the macOS setup experience. With Fleet, organization ## Prerequisites -To use this flow, we must have Apple MDM enabled in Fleet and a macOS host ready to set up in [Apple Business Manager (ABM)](https://business.apple.com/) linked to our Fleet MDM server. +To use this flow, we must have Apple MDM enabled in Fleet and a macOS host ready to set up in [Apple Business (AB)](https://business.apple.com/) linked to our Fleet MDM server. -### What is Apple Business Manager? +### What is Apple Business? -Apple Business Manager (ABM) is a web-based portal that helps organizations deploy and manage Apple devices, including macOS computers, iPhones, and iPads. ABM provides a centralized platform for IT administrators to purchase hardware, assign devices to Mobile Device Management (MDM) servers, and distribute apps and content. +Apple Business (AB) is a web-based portal that helps organizations deploy and manage Apple devices, including macOS computers, iPhones, and iPads. ABM provides a centralized platform for IT administrators to purchase hardware, assign devices to Mobile Device Management (MDM) servers, and distribute apps and content. ![Mac mini in ABM](../website/assets/images/articles/end-user-authentication-mac-in-abm-1354x920@2x.png "Mac mini in ABM") ### Apple's ADE vs DEP -Apple's Device Enrollment Program (DEP) was the original, separate Apple service designed to register and configure devices automatically through an MDM solution. Subsequently, Apple rolled DEP into Automated Device Enrollment (ADE) as part of Apple Business Manager, combining DEP's automatic provisioning with other services in a streamlined portal. The terms ADE and DEP are often used interchangeably. +Apple's Device Enrollment Program (DEP) was the original, separate Apple service designed to register and configure devices automatically through an MDM solution. Subsequently, Apple rolled DEP into Automated Device Enrollment (ADE) as part of Apple Business, combining DEP's automatic provisioning with other services in a streamlined portal. The terms ADE and DEP are often used interchangeably. ## Setting up end-user authentication diff --git a/articles/enroll-hosts.md b/articles/enroll-hosts.md index be6706e6736..da163a32cbd 100644 --- a/articles/enroll-hosts.md +++ b/articles/enroll-hosts.md @@ -6,7 +6,7 @@ To manually enroll macOS, Windows, and Linux hosts, install Fleet’s agent (fle For iOS, iPadOS, and Android hosts, share the enrollment link from the [Fleet UI](#ui) with your end users. End users with Apple's [Stolen Device Protection](https://support.apple.com/en-us/120340) enabled may have to wait 1 hour before they can enroll, depending on their current location. -You can also automatically enroll macOS, Windows, iOS, and iPadOS hosts. To automatically enroll Apple (macOS, iOS, and iPadOS) hosts, [connect Fleet to Apple Business Manager (ABM)](https://fleetdm.com/guides/macos-mdm-setup#apple-business-manager-abm). To automatically enroll Windows hosts, [connect Fleet to Microsoft Entra](https://fleetdm.com/guides/windows-mdm-setup#automatic-enrollment). +You can also automatically enroll macOS, Windows, iOS, and iPadOS hosts. To automatically enroll Apple (macOS, iOS, and iPadOS) hosts, [connect Fleet to Apple Business (AB)](https://fleetdm.com/guides/macos-mdm-setup#apple-business-manager-abm). To automatically enroll Windows hosts, [connect Fleet to Microsoft Entra](https://fleetdm.com/guides/windows-mdm-setup#automatic-enrollment). To learn how to enroll Chromebooks, see the [Enroll Chromebooks guide](#enroll-chromebooks). diff --git a/articles/enroll-macbook-neo-at-scale-with-fleet-zero-touch.md b/articles/enroll-macbook-neo-at-scale-with-fleet-zero-touch.md index 98c9e9f4a76..ce7c82a8994 100644 --- a/articles/enroll-macbook-neo-at-scale-with-fleet-zero-touch.md +++ b/articles/enroll-macbook-neo-at-scale-with-fleet-zero-touch.md @@ -2,7 +2,7 @@ Thinking about refreshing corporate laptops with the new low-cost MacBook Neo? You're not alone. Apple's $599 notebook has sparked a wave of enterprise interest, and IT teams are already planning large-scale rollouts. The question isn't whether to buy them. It's how to enroll hundreds or thousands of them without drowning in manual setup. -This article covers why MacBook Neo matters for enterprise Mac adoption, how Fleet's zero-touch enrollment works with Apple Business Manager, and what IT teams need to do to prepare for a large rollout. +This article covers why MacBook Neo matters for enterprise Mac adoption, how Fleet's zero-touch enrollment works with Apple Business, and what IT teams need to do to prepare for a large rollout. ## MacBook Neo and the enterprise Mac moment @@ -29,11 +29,11 @@ Zero-touch enrollment eliminates this bottleneck. Devices ship directly from App ## How Fleet zero-touch enrollment works -Fleet integrates with [Apple Business Manager (ABM)](https://fleetdm.com/guides/macos-mdm-setup#apple-business-manager-abm) to support zero-touch enrollment through Apple's Automated Device Enrollment (ADE). Here's how the pieces fit together: +Fleet integrates with [Apple Business (AB)](https://fleetdm.com/guides/macos-mdm-setup#apple-business-manager-abm) to support zero-touch enrollment through Apple's Automated Device Enrollment (ADE). Here's how the pieces fit together: -1. **Purchase devices through Apple or an authorized reseller.** When you buy MacBook Neos through an authorized channel and provide your ABM Organization ID, each device's serial number is automatically registered to your Apple Business Manager account. +1. **Purchase devices through Apple or an authorized reseller.** When you buy MacBook Neos through an authorized channel and provide your ABM Organization ID, each device's serial number is automatically registered to your Apple Business account. -2. **Assign devices to Fleet in Apple Business Manager.** In the ABM portal, assign the registered serial numbers to your Fleet MDM server. This tells Apple's activation servers to direct those devices to Fleet when they first boot up. +2. **Assign devices to Fleet in Apple Business.** In the ABM portal, assign the registered serial numbers to your Fleet MDM server. This tells Apple's activation servers to direct those devices to Fleet when they first boot up. 3. **Configure enrollment settings in Fleet.** Set up your [enrollment profile](https://fleetdm.com/guides/setup-experience), including which Setup Assistant screens to show or skip, whether to require end user authentication, and which team to assign the device to. Fleet also supports a [bootstrap package](https://fleetdm.com/guides/manage-boostrap-package-with-gitops) for installing essential software during first setup. @@ -48,7 +48,7 @@ This workflow scales the same way whether you're enrolling 10 devices or 10,000. Before placing a large MacBook Neo order, make sure your Fleet infrastructure is ready. Here's a practical checklist for IT teams planning a rollout: -### Verify Apple Business Manager setup +### Verify Apple Business setup - Confirm your [ABM account](https://fleetdm.com/articles/what-is-apple-business-manager-a-complete-guide) is verified and active with a valid D-U-N-S number. - Ensure your Fleet MDM server is added as a virtual MDM server in ABM. @@ -90,13 +90,13 @@ These capabilities apply across macOS, Windows, and Linux, so if you're adding M The MacBook Neo has changed the economics of enterprise Mac adoption. As Evans wrote, this device has sparked "the kind of curiosity you saw with the iMac and the iPad" among people who have never owned an Apple notebook. For IT teams, that interest translates into a real planning exercise: how do you take advantage of a $599 Mac without creating an operational headache? -Fleet's zero-touch enrollment, combined with Apple Business Manager, gives you a repeatable, scalable process for getting MacBook Neos into employees' hands fully configured and secured from first boot. No staging facility, no manual imaging, no configuration drift. +Fleet's zero-touch enrollment, combined with Apple Business, gives you a repeatable, scalable process for getting MacBook Neos into employees' hands fully configured and secured from first boot. No staging facility, no manual imaging, no configuration drift. -If you're evaluating a MacBook Neo rollout, [connect Fleet to Apple Business Manager](https://fleetdm.com/guides/macos-mdm-setup#apple-business-manager-abm) and test the enrollment workflow before placing your order. You can also [try Fleet](https://fleetdm.com/register) to see the full MDM experience firsthand. +If you're evaluating a MacBook Neo rollout, [connect Fleet to Apple Business](https://fleetdm.com/guides/macos-mdm-setup#apple-business-manager-abm) and test the enrollment workflow before placing your order. You can also [try Fleet](https://fleetdm.com/register) to see the full MDM experience firsthand. - + diff --git a/articles/enroll-personal-byod-ios-ipad-hosts-with-managed-apple-account.md b/articles/enroll-personal-byod-ios-ipad-hosts-with-managed-apple-account.md index 2e735fb9769..47c7b926e27 100644 --- a/articles/enroll-personal-byod-ios-ipad-hosts-with-managed-apple-account.md +++ b/articles/enroll-personal-byod-ios-ipad-hosts-with-managed-apple-account.md @@ -8,29 +8,32 @@ In Fleet, you can allow your end users to enroll their personal iPhones and iPad With Account-driven User Enrollment, end users can separate work and personal data using their [Managed Apple Account](https://support.apple.com/en-gb/guide/apple-business-manager/axm78b477c81/web). End users retain privacy over their personal information, while IT admins manage work-related OS settings and applications. -- [Step 1: Connect Apple Business Manager (ABM) to Fleet](#step-1-connect-apple-business-manager-abm-to-fleet) -- [Step 2: Add and verify your domain in Apple Business Manager (ABM)](#step-2-add-and-verify-your-domain-in-apple-business-manager-abm) -- [Step 3: Connect (federate) your identity provider (IdP) with Apple Business Manager (ABM)](#step-3-connect-federate-your-identity-provider-idp-with-apple-business-manager-abm) +- [Step 1: Connect Apple Business (AB) to Fleet](#step-1-connect-apple-business-manager-abm-to-fleet) +- [Step 2: Add and verify your domain in Apple Business (AB)](#step-2-add-and-verify-your-domain-in-apple-business-manager-abm) +- [Step 3: Connect (federate) your identity provider (IdP) with Apple Business (AB)](#step-3-connect-federate-your-identity-provider-idp-with-apple-business-manager-abm) - [Step 4: Create a fleet for personal hosts](#step-4-create-a-fleet-for-personal-hosts) - [Step 5: Log in on the device to enroll to Fleet (end user's iPhone or iPad)](#step-5-log-in-on-the-device-to-enroll-to-fleet-end-users-iphone-or-ipad) -## Step 1: Connect Apple Business Manager (ABM) to Fleet +## Step 1: Connect Apple Business (AB) to Fleet -1. Follow the [instructions](https://fleetdm.com/guides/macos-mdm-setup#apple-business-manager-abm) to connect ABM to Fleet. -> **Note:** You may skip this if you have already connected ABM to enable automatic enrollment. -2. For Account-driven User Enrollment to work, ensure that personal (BYOD) iOS and iPadOS hosts are associated with Fleet in the **Default Server Assignment** section in Apple Business Manager. -> **Note:** If you're trying Fleet and testing Account-driven User Enrollment, [self-host a service discovery file](#self-host-a-service-discovery-file-well-known-resource) instead. That way, hosts keep enrolling to your current MDM solution instead of Fleet. +1. If you haven't already, follow the [Apple Business (AB) instructions](https://fleetdm.com/guides/macos-mdm-setup#apple-business-manager-abm) to connect it to Fleet. -## Step 2: Add and verify your domain in Apple Business Manager (ABM) +2. In ABM, go to **Preferences > Management Assignment** and make sure the **Default Assignment** for iPads and iPhones is set to Fleet. + +If you're testing Account-driven User Enrollment with Fleet, switch the **Default Assignment** when no iPads or iPhones are expected to enroll, then switch it back when you're done. + +To keep non–Account-driven enrollments on your current MDM while sending only Account-driven enrollments to Fleet, you can [self-host a service discovery file](#self-host-a-service-discovery-file-well-known-resource). + +## Step 2: Add and verify your domain in Apple Business (AB) Follow the [Apple documentation](https://support.apple.com/en-gb/guide/apple-business-manager/axm48c3280c0/web#axm2033c47b0) to add and verify your company domain in your ABM. Use the domain name associated with your work email (for example, `yourcompany.com` from `name@yourcompany.com`). This will enable the automatic creation of Apple Managed Accounts from your identity provider (IdP) accounts in the next step. -## Step 3: Connect (federate) your identity provider (IdP) with Apple Business Manager (ABM) +## Step 3: Connect (federate) your identity provider (IdP) with Apple Business (AB) Follow the [Apple documentation](https://support.apple.com/en-gb/guide/apple-business-manager/axmb19317543/web) to connect your identity provider (IdP). This will enable end users to log in to their Managed Apple Account using their existing IdP credentials. -> **Note:** For visual walk-throughs, see [Connect Google Workspace to ABM](https://www.youtube.com/watch?v=CPfO6W67d3A) and [Connect Microsoft Entra ID to ABM](https://www.youtube.com/watch?v=_-PnhMurAVk). +> For visual walk-throughs, see [Connect Google Workspace to ABM](https://www.youtube.com/watch?v=CPfO6W67d3A) and [Connect Microsoft Entra ID to ABM](https://www.youtube.com/watch?v=_-PnhMurAVk). ## Step 4: Create a fleet for personal hosts @@ -51,14 +54,14 @@ After signing in, the device will automatically enroll in Fleet. ## Self-host a service discovery file (well-known resource) ->**Note:** -> - If your iOS/iPadOS hosts are running version 18.2 or later, you can skip this. Fleet manages service discovery automatically for these versions. -> - If your iOS/iPadOS hosts are running a version below 18.2 or you're trying Fleet, you'll need to self-host a [service discovery JSON file](https://support.apple.com/en-gb/guide/deployment/dep4d9e9cd26/web#depcae01b5df). -> - If you're trying Fleet and using a different MDM solution in production, hosting this file will direct only Account-driven User Enrollments to Fleet. iOS/iPadOS hosts purchased in ABM and hosts using an enrollment profile will still enroll to your current MDM solution. +- If your iOS/iPadOS hosts are running version 18.2 or later, skip this step. Fleet manages service discovery automatically for these versions. +- If your iOS/iPadOS hosts are running a version below 18.2, self-host a [service discovery JSON file](https://support.apple.com/en-gb/guide/deployment/dep4d9e9cd26/web#depcae01b5df). + +> **Note:** If you're using another MDM in production, hosting this file sends only Account-driven User Enrollments to Fleet. Devices enrolled through ABM or an enrollment profile will continue to enroll in your current MDM. Host the JSON file below at the following URL: `https:///.well-known/com.apple.remotemanagement.` -> **Note:** Make sure to include the trailing dot in the URL when hosting the file. +> Include the trailing dot in the URL when hosting the file. Make sure the `Content-Type` header is set to `application/json`. diff --git a/articles/fleet-management-software.md b/articles/fleet-management-software.md index 52919b2db16..ce16be4f580 100644 --- a/articles/fleet-management-software.md +++ b/articles/fleet-management-software.md @@ -53,9 +53,9 @@ Fleet, Jamf, and Intune all handle core device management functions: enrollment, ### Enrollment and provisioning -All three solutions support zero-touch deployment for the platforms they support. Apple devices enroll through Apple Business Manager. In Fleet and Intune, Windows devices use Windows Autopilot. All three solutions can configure settings that prevent end users from tampering with management profiles. +All three solutions support zero-touch deployment for the platforms they support. Apple devices enroll through Apple Business. In Fleet and Intune, Windows devices use Windows Autopilot. All three solutions can configure settings that prevent end users from tampering with management profiles. -Jamf Pro's PreStage enrollment configures Apple device onboarding, including signed package deployment during setup. Intune's Autopilot configures Windows device onboarding with comparable automation. Intune also support Apple's Automated Device Enollemnt (ADE) via ABM. Fleet supports both Apple Business Manager and Windows Autopilot, providing consistent zero-touch enrollment across a mixed device fleet. +Jamf Pro's PreStage enrollment configures Apple device onboarding, including signed package deployment during setup. Intune's Autopilot configures Windows device onboarding with comparable automation. Intune also support Apple's Automated Device Enollemnt (ADE) via AB. Fleet supports both Apple Business and Windows Autopilot, providing consistent zero-touch enrollment across a mixed device fleet. ### Configuration management @@ -115,7 +115,7 @@ Fleet provides consistent multi-platform capabilities where Jamf Pro is Apple-fi #### How long does it take to roll out device management software? -Timelines depends on fleet size and configuration complexity. Fleet supports zero-touch enrollment through Apple Business Manager and Windows Autopilot for automated onboarding. Fleet also provides MDM migration workflows and professional services for organizations transitioning from other solutions. [Schedule a demo](https://fleetdm.com/contact) to discuss your rollout timeline. +Timelines depends on fleet size and configuration complexity. Fleet supports zero-touch enrollment through Apple Business and Windows Autopilot for automated onboarding. Fleet also provides MDM migration workflows and professional services for organizations transitioning from other solutions. [Schedule a demo](https://fleetdm.com/contact) to discuss your rollout timeline. diff --git a/articles/fleet-now-supports-ios-and-ipados-software-deployment-and-automated-patch-management.md b/articles/fleet-now-supports-ios-and-ipados-software-deployment-and-automated-patch-management.md index 25a89c1a486..2ae36f34f59 100644 --- a/articles/fleet-now-supports-ios-and-ipados-software-deployment-and-automated-patch-management.md +++ b/articles/fleet-now-supports-ios-and-ipados-software-deployment-and-automated-patch-management.md @@ -25,9 +25,9 @@ Fleet enables organizations to assign and install Apple App Store apps purchased By integrating VPP app distribution into the Fleet Desktop Self-Service portal, organizations can streamline the deployment of essential software across their macOS devices. This ensures that users have easy access to the tools they need while maintaining control over software distribution. This update enhances the overall user experience and operational efficiency, empowering end users to install approved applications with minimal IT intervention. -### Multiple Apple Business Manager and VPP support +### Multiple Apple Business and VPP support -Alongside initial Volume Purchase Program (VPP) support, now you can add and manage multiple Apple Business Manager (ABM) and VPP tokens within a single Fleet instance. This feature is designed for both Managed Service Providers (MSPs) and large enterprises. Whether an MSP or an enterprise with multiple divisions, admins can set up separate workflows to automatically enroll devices and distribute apps through the App Store. This update simplifies the process of handling macOS, iOS, and iPadOS devices, providing a scalable solution for both MSPs and enterprises looking to centralize control while maintaining flexibility for different user groups. +Alongside initial Volume Purchase Program (VPP) support, now you can add and manage multiple Apple Business (AB) and VPP tokens within a single Fleet instance. This feature is designed for both Managed Service Providers (MSPs) and large enterprises. Whether an MSP or an enterprise with multiple divisions, admins can set up separate workflows to automatically enroll devices and distribute apps through the App Store. This update simplifies the process of handling macOS, iOS, and iPadOS devices, providing a scalable solution for both MSPs and enterprises looking to centralize control while maintaining flexibility for different user groups. ![Add software modal](../website/assets/images/articles/fleet-now-supports-ios-and-ipados-software-deployment-and-automated-patch-management-1-2000x1000@2x.png "Add software modal.") *Add software modal.* diff --git a/articles/fleet-supports-macos-26-tahoe-ios-26-and-ipados-26.md b/articles/fleet-supports-macos-26-tahoe-ios-26-and-ipados-26.md index 5294dc0ab16..e854a0fed62 100644 --- a/articles/fleet-supports-macos-26-tahoe-ios-26-and-ipados-26.md +++ b/articles/fleet-supports-macos-26-tahoe-ios-26-and-ipados-26.md @@ -7,21 +7,25 @@ _Photo by [MariuszBlach](https://www.istockphoto.com/photo/lake-tahoe-gm48064107 With Apple's releases of macOS Tahoe 26, iOS 26, and iPadOS 26, Fleet provides same-day support for IT teams to upgrade immediately so devices will remain secure and fully managed. This means that all existing Fleet features are tested and bugs are fixed. Also, Fleet will support these new features: -- MDM migration with Apple Business Manager (ABM) +- MDM migration with Apple Business (AB) - Declarative device management (DDM) OS updates and profiles - Platform Single Sign-on during new Mac setup (coming soon) All new features go through Fleet's [prioritization process](https://fleetdm.com/handbook/company/product-groups#how-feature-requests-are-prioritized). Excited about a new feature in macOS Tahoe? You can file a [feature request](https://github.com/fleetdm/fleet/issues/new?template=feature-request.md). -## MDM migration with Apple Business Manager (ABM) +## MDM migration with Apple Business (AB) With macOS Tahoe 26, iOS 26, and iPadOS 26, Apple introduces Device Management Migration: an improved workflow for migrating devices from one management service (MDM) to another. Learn more about configuring and the end user experience in the [Apple docs](https://support.apple.com/guide/deployment/migrate-managed-devices-dep4acb2aa44/web). -In Apple Business Manager (ABM), admins can assign devices to a new MDM server and set a migration deadline. Users receive clear notifications that enrollment into a new management service is required. If users do not act before the migration deadline, enrollment into the new MDM is enforced automatically, eliminating the need for device wipes, scripts, or manual workarounds that previously made MDM migrations more difficult, complex and time-consuming. +If you're planning a macOS migration with the Tahoe workflow: -Fleet is ready to support this migration workflow, making it easier for organizations to migrate devices with minimal disruption. +- Migrate devices in batches of around 100. +- Alternate batches between Mondays and Wednesdays. +- Set a 1–2 week deadline for each batch. +- Before the first batch, export a device list with each end user's name. +- Group devices into batches in a spreadsheet so stakeholders can plan around travel or other conflicts. -> If the MDM migration fails, don’t reassign the host to your old MDM in Apple Business Manager (ABM). Reassigning makes the host ineligible for migration. The host must stay actively enrolled in the MDM it’s migrating from. Once you change the ABM assignment, ABM treats the host as no longer enrolled, and the migration can’t continue. +> If the MDM migration fails, don’t reassign the host to your old MDM in Apple Business (AB). Reassigning makes the host ineligible for migration. The host must stay actively enrolled in the MDM it’s migrating from. Once you change the ABM assignment, AB treats the host as no longer enrolled, and the migration can’t continue. ## Declarative device management (DDM) OS updates and profiles diff --git a/articles/fleet-vs-jamf-pro-ninjaone-mdm-comparison.md b/articles/fleet-vs-jamf-pro-ninjaone-mdm-comparison.md index edf5ce53f9d..1b5cd91d028 100644 --- a/articles/fleet-vs-jamf-pro-ninjaone-mdm-comparison.md +++ b/articles/fleet-vs-jamf-pro-ninjaone-mdm-comparison.md @@ -1,8 +1,8 @@ ## Overview -Fleet is an open-source, multi-platform device management solution supporting macOS, Windows, Linux, iOS, iPadOS, ChromeOS, and Android. Fleet provides zero-touch deployment through Apple Business Manager or Apple School Manager and Declarative Device Management (DDM), with native GitOps workflows for version-controlled configuration management. Fleet’s [osquery](https://fleetdm.com/guides/osquery-a-tool-to-easily-ask-questions-about-operating-systems) foundation delivers near real-time device reporting across all platforms. Organizations can self-host or be hosted in Fleet’s managed-cloud environment with [MDM migration](https://fleetdm.com/guides/mdm-migration) support for transitions from your management service. +Fleet is an open-source, multi-platform device management solution supporting macOS, Windows, Linux, iOS, iPadOS, ChromeOS, and Android. Fleet provides zero-touch deployment through Apple Business or Apple School Manager and Declarative Device Management (DDM), with native GitOps workflows for version-controlled configuration management. Fleet’s [osquery](https://fleetdm.com/guides/osquery-a-tool-to-easily-ask-questions-about-operating-systems) foundation delivers near real-time device reporting across all platforms. Organizations can self-host or be hosted in Fleet’s managed-cloud environment with [MDM migration](https://fleetdm.com/guides/mdm-migration) support for transitions from your management service. -Jamf Pro is an Apple-focused Mobile Device Management (MDM) solution supporting macOS, iOS, iPadOS, tvOS, visionOS, and watchOS devices, and it also supports Android. Jamf Pro provides zero-touch deployment through Apple Business Manager and Apple School Manager. Jamf Pro offers cloud-hosted deployment only, with on-premises support deprecated. Jamf Pro does not [support Windows](https://fleetdm.com/announcements/fleet-introduces-windows-mdm) or Linux devices natively, so organizations with mixed environments need additional management solutions. +Jamf Pro is an Apple-focused Mobile Device Management (MDM) solution supporting macOS, iOS, iPadOS, tvOS, visionOS, and watchOS devices, and it also supports Android. Jamf Pro provides zero-touch deployment through Apple Business and Apple School Manager. Jamf Pro offers cloud-hosted deployment only, with on-premises support deprecated. Jamf Pro does not [support Windows](https://fleetdm.com/announcements/fleet-introduces-windows-mdm) or Linux devices natively, so organizations with mixed environments need additional management solutions. NinjaOne is a cloud-native IT management solution combining remote monitoring and management (RMM) with MDM capabilities for Windows, macOS, Linux, iOS, iPadOS, and Android devices. NinjaOne provides cross-platform coverage and patch management through a unified console. Both Jamf Pro and NinjaOne are proprietary solutions, while Fleet is open-source. @@ -29,7 +29,7 @@ NinjaOne is a cloud-native IT management solution combining remote monitoring an ### Enrollment and provisioning -Fleet, Jamf Pro, and NinjaOne support zero-touch enrollment for Apple devices through Apple Business Manager. +Fleet, Jamf Pro, and NinjaOne support zero-touch enrollment for Apple devices through Apple Business. Fleet supports Windows enrollment via Windows Autopilot, and Windows Autopilot requires Microsoft Entra ID. Jamf Pro’s zero-touch enrollment capabilities focus on Apple platforms it supports (macOS, iOS/iPadOS, tvOS, visionOS, and watchOS). @@ -53,7 +53,7 @@ Software deployment and patching work differently across these three solutions. Fleet combines software deployment with built-in vulnerability detection, identifying CVEs across all platforms and enabling policy-based automatic remediation when vulnerable software is detected. Fleet enables App Store app installations and offers the Fleet-maintained app catalog for easy deployment. -Jamf Pro handles Apps and Books deployment for Apple devices through Apple Business Manager integration. Jamf Pro includes App Installers for easy deployment. +Jamf Pro handles Apps and Books deployment for Apple devices through Apple Business integration. Jamf Pro includes App Installers for easy deployment. NinjaOne includes OS patch management for Windows, macOS, and Linux, plus third-party application patching primarily for Windows, with deployment flowing through its agent. NinjaOne recently added 3rd party vulnerability visibility, but Fleet's approach integrates CVE detection with CISA KEV and EPSS scoring to help security teams prioritize what to patch first. @@ -95,11 +95,11 @@ Open-source tools like Fleet provide code that organizations can audit, modify, #### How do multi-platform MDM tools compare with Apple-only options for managing Apple devices? -Multi-platform tools like Fleet provide complete Apple device management capabilities at parity with Apple-focused tools, including zero-touch enrollment through Apple Business Manager, MDM Configuration Profiles, and Apps and Books (VPP) distribution. Organizations using multiple operating systems can consolidate tools rather than running separate solutions for each platform. Schedule a demo to see how [Fleet](https://fleetdm.com/device-management) manages Apple devices alongside Windows and Linux. +Multi-platform tools like Fleet provide complete Apple device management capabilities at parity with Apple-focused tools, including zero-touch enrollment through Apple Business, MDM Configuration Profiles, and Apps and Books (VPP) distribution. Organizations using multiple operating systems can consolidate tools rather than running separate solutions for each platform. Schedule a demo to see how [Fleet](https://fleetdm.com/device-management) manages Apple devices alongside Windows and Linux. #### Can I migrate from Jamf Pro to Fleet without disrupting device management? -Fleet supports gradual migration from Jamf Pro and other MDM solutions. You can run Fleet alongside your existing MDM during the transition, moving devices incrementally while maintaining management continuity. Fleet's Apple Business Manager integration has full compatibility with Apple’s Managed Device Migration and configuration profiles can be deployed through Fleet's GitOps workflows. Schedule a demo to discuss your Jamf migration timeline. +Fleet supports gradual migration from Jamf Pro and other MDM solutions. You can run Fleet alongside your existing MDM during the transition, moving devices incrementally while maintaining management continuity. Fleet's Apple Business integration has full compatibility with Apple’s Managed Device Migration and configuration profiles can be deployed through Fleet's GitOps workflows. Schedule a demo to discuss your Jamf migration timeline. #### How does Fleet's security visibility compare to Jamf Pro and NinjaOne? diff --git a/articles/gitops-mode-software.md b/articles/gitops-mode-software.md index 3e82ddec465..bc23450d828 100644 --- a/articles/gitops-mode-software.md +++ b/articles/gitops-mode-software.md @@ -21,7 +21,7 @@ If you want to use Fleet to host custom packages instead of a third-party packag ## App store apps -To manage Apple App Store (VPP) or Android Google Play apps via GitOps, please see the [`app_store_apps`](https://fleetdm.com/docs/configuration/yaml-files#app-store-apps) in Fleet's best practice GitOps docs. Note that VPP apps must first be added to [Apple Business Manager](https://business.apple.com). +To manage Apple App Store (VPP) or Android Google Play apps via GitOps, please see the [`app_store_apps`](https://fleetdm.com/docs/configuration/yaml-files#app-store-apps) in Fleet's best practice GitOps docs. Note that VPP apps must first be added to [Apple Business](https://business.apple.com). ## Fleet-maintained apps diff --git a/articles/how-to-manage-company-laptops-a-complete-guide.md b/articles/how-to-manage-company-laptops-a-complete-guide.md index dd2dab3a0d0..038ce3d9721 100644 --- a/articles/how-to-manage-company-laptops-a-complete-guide.md +++ b/articles/how-to-manage-company-laptops-a-complete-guide.md @@ -27,7 +27,7 @@ Secure onboarding starts before the device reaches the employee. The goal is zer ### Apple devices: Automated Device Enrollment -Apple Business Manager (ABM) links device serial numbers to an organization's MDM server. When a new Mac powers on, it contacts Apple's activation servers, identifies the assigned MDM, and enrolls automatically during Setup Assistant. Devices enrolled through Automated Device Enrollment (ADE) can be configured as supervised, which prevents users from removing the MDM profile and enables additional management capabilities. Once enrolled, configuration profiles, encryption settings, and applications can deploy automatically. +Apple Business (AB) links device serial numbers to an organization's MDM server. When a new Mac powers on, it contacts Apple's activation servers, identifies the assigned MDM, and enrolls automatically during Setup Assistant. Devices enrolled through Automated Device Enrollment (ADE) can be configured as supervised, which prevents users from removing the MDM profile and enables additional management capabilities. Once enrolled, configuration profiles, encryption settings, and applications can deploy automatically. A few details that often trip teams up: Apple Push Notification service (APNs) certificates need renewal before they expire or enrolled devices may stop receiving new commands, Setup Assistant flows should be tested on the same macOS version being shipped, and splitting profiles by function (security restrictions separate from VPN settings) reduces change risk. @@ -105,7 +105,7 @@ In practice, teams get fewer surprises when access removal is separated from dev * **Revoke identity access first:** Disable the user in your identity provider and enforce conditional access so the laptop can't reach corporate resources even if it stays online. * **Handle legal hold before wiping:** Decide whether data needs to be preserved for legal hold or investigation. A full wipe is final, so the wipe step should align with your HR and legal processes. -* **Reset for reassignment:** Prepare the laptop for reassignment. For Macs, this may involve a manual wipe-and-reenroll cycle, or the device can be reassigned through Apple Business Manager. +* **Reset for reassignment:** Prepare the laptop for reassignment. For Macs, this may involve a manual wipe-and-reenroll cycle, or the device can be reassigned through Apple Business. If device management integrates with the identity provider, offboarding becomes less dependent on someone remembering a checklist. For example, disabling a user account in Microsoft Entra ID or Okta can trigger conditional access policies that block the device from corporate resources. diff --git a/articles/install-app-store-apps.md b/articles/install-app-store-apps.md index 90f2e51ba0f..edf492e8842 100644 --- a/articles/install-app-store-apps.md +++ b/articles/install-app-store-apps.md @@ -12,7 +12,7 @@ You can also manage which Google Play Store apps are available for self-service > Before using Fleet to manage VPP apps, you must first [turn on Apple MDM](https://fleetdm.com/guides/apple-mdm-setup#turn-on-apple-mdm) and Apple's [Volume Purchasing Program (VPP)](https://fleetdm.com/guides/apple-mdm-setup#volume-purchasing-program-vpp). Once you've completed that setup, you can follow the directions below for each app. -1. Purchase the relevant app through Apple Business Manager (ABM). You must perform this step even if the app is free, or if it is a custom app you own. Learn how in [Apple's documentation](https://support.apple.com/guide/apple-business-manager/select-and-buy-content-axmc21817890/web). +1. Purchase the relevant app through Apple Business (AB). You must perform this step even if the app is free, or if it is a custom app you own. Learn how in [Apple's documentation](https://support.apple.com/guide/apple-business-manager/select-and-buy-content-axmc21817890/web). 2. In Fleet, head to the **Software** page and select a fleet in the fleets dropdown. diff --git a/articles/ipad-mdm-a-complete-guide.md b/articles/ipad-mdm-a-complete-guide.md index d732e5d80b4..d934215175d 100644 --- a/articles/ipad-mdm-a-complete-guide.md +++ b/articles/ipad-mdm-a-complete-guide.md @@ -53,7 +53,7 @@ This works across any internet connection assuming the MDM server is configured Organizations can choose from three enrollment methods that provide different management capabilities depending on device ownership: -- **Automated Device Enrollment (ADE)** through Apple Business Manager (ABM) or Apple School Manager (ASM) provides the most streamlined approach for devices purchased through Apple or authorized Apple reseller channels. Devices automatically contact Apple services and walk the end user through a guided Setup Assistant workflow and an automated provisioning process resulting in a fully-managed device on-demand without admin interaction or IT help. +- **Automated Device Enrollment (ADE)** through Apple Business (AB) or Apple School Manager (ASM) provides the most streamlined approach for devices purchased through Apple or authorized Apple reseller channels. Devices automatically contact Apple services and walk the end user through a guided Setup Assistant workflow and an automated provisioning process resulting in a fully-managed device on-demand without admin interaction or IT help. - **User Enrollment** creates separate management on the device for corporate apps, data and access to resources while maintaining strict privacy boundaries around personal data which can't be deleted via management. @@ -63,13 +63,13 @@ The enrollment method chosen determines the level of control an organization has ### Supervised vs. unsupervised capabilities -Supervision determine which MDM features are available on enrolled devices. Getting devices supervised requires either Automated Device Enrollment through Apple Business Manager or Apple School Manager during initial setup or using Apple Configurator with physical USB connectivity to each device. +Supervision determine which MDM features are available on enrolled devices. Getting devices supervised requires either Automated Device Enrollment through Apple Business or Apple School Manager during initial setup or using Apple Configurator with physical USB connectivity to each device. Two supervision levels serve different organizational needs: - **Supervision** - Organizations can unlock advanced capabilities that address enterprise requirements, like: - - De[ploying managed apps + - Deploying managed apps - Hiding specific Apple native applications from home screens - Making MDM management immutable so end users can't remove the MDM profile - Restricting data exfiltration paths like AirDrop and Sharing @@ -82,7 +82,7 @@ An institutionally-owned iPad deployed 1:1 for a single employee as a primary wo > Supervised devices can't be converted to unsupervised devices without erasing all data contained on them and re-enrolling them into MDM. -### Apple Business Manager and Apple School Manager integration +### Apple Business and Apple School Manager integration ABM and ASM integration allows your organization to easily grow your iPad deployments to enterprise scale. ABM / ASM administrators can assign devices to one or many MDM servers in the portal. In addition, most MDM solutions allow for multiple enrollment groupings, meaning enrollment can be customized for potentially unique deployments like special-use iPads if needed. diff --git a/articles/lock-wipe-hosts.md b/articles/lock-wipe-hosts.md index 3870a2f9a9d..92f7907e63f 100644 --- a/articles/lock-wipe-hosts.md +++ b/articles/lock-wipe-hosts.md @@ -53,7 +53,7 @@ Example URL: When wiping and re-installing the operating system (OS) on a host, delete the host from Fleet before you re-enroll it. If you re-enroll without deleting, Fleet won't escrow a new disk encryption key. -If you're gifting a company-owned macOS host or you want to prevent the host from automatically re-enrolling to Fleet for some other reason, first release the host from Apple Business Manager (ABM) and then delete the host in Fleet. +If you're gifting a company-owned macOS host or you want to prevent the host from automatically re-enrolling to Fleet for some other reason, first release the host from Apple Business (AB) and then delete the host in Fleet. For Windows hosts, Fleet uses the [doWipeProtected](https://learn.microsoft.com/en-us/windows/client-management/mdm/remotewipe-csp#dowipeprotected) command by default. According to Microsoft, this leaves the host [unable to boot](https://learn.microsoft.com/en-us/windows/client-management/mdm/remotewipe-csp#:~:text=In%20some%20device%20configurations%2C%20this%20command%20may%20leave%20the%20device%20unable%20to%20boot.). However, it is possible to use the [doWipe command via the API](https://fleetdm.com/docs/rest-api/rest-api#parameters57). diff --git a/articles/mac-device-security.md b/articles/mac-device-security.md index 09e00205f31..90af8685464 100644 --- a/articles/mac-device-security.md +++ b/articles/mac-device-security.md @@ -87,7 +87,7 @@ For organizations managing mixed fleets, unified MDM visibility across Mac, Wind When selecting an MDM, verify these capabilities across all operating systems you manage: -* Zero-touch enrollment through Apple Business Manager +* Zero-touch enrollment through Apple Business * Configuration profile deployment and verification * Software deployment and patch management * Compliance monitoring aligned with NIST mSCP baselines diff --git a/articles/mac-inventory-management.md b/articles/mac-inventory-management.md index f10ff710611..ec261741e1a 100644 --- a/articles/mac-inventory-management.md +++ b/articles/mac-inventory-management.md @@ -38,11 +38,11 @@ Apple's Mobile Device Management framework provides the technical foundation for ### Enrollment and initial registration -Devices enroll through Apple Business Manager for zero-touch deployment or through user-initiated enrollment for existing Macs and BYOD scenarios. During enrollment, devices install the management profile and use APNs to receive MDM notifications, then contact the MDM server to exchange commands and inventory data. +Devices enroll through Apple Business for zero-touch deployment or through user-initiated enrollment for existing Macs and BYOD scenarios. During enrollment, devices install the management profile and use APNs to receive MDM notifications, then contact the MDM server to exchange commands and inventory data. The enrollment process captures initial device identifiers including UDID, serial number, and hardware model, forming the baseline device record that organizations typically reconcile into their HAM system. -Organizations using Apple Business Manager can assign devices by serial number through Automated Device Enrollment (ADE) before they ship, enabling automatic MDM enrollment when users power them on for the first time. This architecture removes the need to physically handle devices for inventory registration in most cases, supporting remote workforce scenarios where Macs ship directly to employee homes. +Organizations using Apple Business can assign devices by serial number through Automated Device Enrollment (ADE) before they ship, enabling automatic MDM enrollment when users power them on for the first time. This architecture removes the need to physically handle devices for inventory registration in most cases, supporting remote workforce scenarios where Macs ship directly to employee homes. ### Continuous data collection through MDM queries @@ -66,7 +66,7 @@ Scaling Mac inventory management across hundreds or thousands of devices require ### 1. Implement zero-touch deployment workflows -Integrate Apple Business Manager with your MDM tool to enable automatic device enrollment. Assign new Macs to your MDM server at the point of purchase, configure Automated Device Enrollment so devices are managed from first boot (and, if desired, the MDM enrollment profile can be non-removable), and integrate with your identity provider for user authentication during enrollment. +Integrate Apple Business with your MDM tool to enable automatic device enrollment. Assign new Macs to your MDM server at the point of purchase, configure Automated Device Enrollment so devices are managed from first boot (and, if desired, the MDM enrollment profile can be non-removable), and integrate with your identity provider for user authentication during enrollment. Tools like Fleet support [zero-touch provisioning through ABM](https://fleetdm.com/docs/using-fleet/mdm-macos-setup), allowing organizations to define enrollment settings, team assignments, and configuration profiles that apply automatically when devices first connect. @@ -106,7 +106,7 @@ This approach supports unified reporting and compliance dashboards while preserv ## Manage your Mac fleet effectively -Mac inventory management works best when you treat device management systems as rich data sources and keep a dedicated Hardware Asset Management (HAM) system as your authoritative system of record. Effective implementation means deploying zero-touch workflows through Apple Business Manager, building data schemas that respect BYOD boundaries, integrating with identity providers, and ensuring the right device data flows into your HAM tool for procurement, assignment, and lifecycle workflows. +Mac inventory management works best when you treat device management systems as rich data sources and keep a dedicated Hardware Asset Management (HAM) system as your authoritative system of record. Effective implementation means deploying zero-touch workflows through Apple Business, building data schemas that respect BYOD boundaries, integrating with identity providers, and ensuring the right device data flows into your HAM tool for procurement, assignment, and lifecycle workflows. Fleet provides an open-source tool that [combines MDM with osquery](https://fleetdm.com/device-management) for macOS, Windows, and Linux. Fleet is not a hardware asset management system, but it can act as a device management and data collection/orchestration layer that captures richer device data more frequently than many device management tools, making it valuable for populating and keeping HAM records current. @@ -128,7 +128,7 @@ The best approach involves implementing check-in requirements where devices must ### Can I use the same inventory collection approach across Mac, Windows, and Linux, or do I need platform-specific tools? -Cross-platform inventory tools exist, but macOS requires platform-specific support due to Apple-specific frameworks, management workflows that depend on the MDM protocol, and Apple Business Manager enrollment patterns. +Cross-platform inventory tools exist, but macOS requires platform-specific support due to Apple-specific frameworks, management workflows that depend on the MDM protocol, and Apple Business enrollment patterns. The most effective approach uses tools with strong native Mac support rather than Windows-centric platforms extended to macOS as an afterthought. Define common inventory fields applicable across all platforms (device name, OS version, assigned user) while maintaining platform-specific extensions for Mac attributes like FileVault status, Apple silicon architecture details, and System Integrity Protection configuration state. @@ -136,7 +136,7 @@ The most effective approach uses tools with strong native Mac support rather tha Look for device management and data collection tooling that can reliably collect the fields your HAM system needs: stable identifiers (serial number, hardware UUID), enrollment metadata, assignment/user mapping, and lifecycle status signals (last check-in, OS version eligibility, encryption state). In addition, ensure you can export or integrate that device data into your HAM system. -Fleet combines Apple's MDM framework with osquery to collect Mac device data across hardware specifications, software versions, and security configurations. Fleet supports zero-touch deployment through Apple Business Manager integration, enabling automatic enrollment and policy enforcement for new devices, and it can provide high-fidelity data that you can use to populate and maintain your hardware asset records in a dedicated HAM solution. +Fleet combines Apple's MDM framework with osquery to collect Mac device data across hardware specifications, software versions, and security configurations. Fleet supports zero-touch deployment through Apple Business integration, enabling automatic enrollment and policy enforcement for new devices, and it can provide high-fidelity data that you can use to populate and maintain your hardware asset records in a dedicated HAM solution. [Try Fleet](https://fleetdm.com/get-started) to evaluate it as a device management and data collection layer for your Mac inventory workflows. diff --git a/articles/mac-zero-touch-deployment-guide.md b/articles/mac-zero-touch-deployment-guide.md index 404da4b6ef2..db54348703a 100644 --- a/articles/mac-zero-touch-deployment-guide.md +++ b/articles/mac-zero-touch-deployment-guide.md @@ -6,7 +6,7 @@ Shipping Mac devices to remote employees typically means either extensive IT han Zero-touch deployment lets organizations ship Macs directly from vendors to end users without IT intervention. When a user opens their box and powers on their new Mac it walks them though a setup assistant, automatically queries Apple's servers, receives its MDM assignment, enrolls itself, and applies the organization's security policies and configuration profiles. -The workflow is enabled by Apple's Automated Device Enrollment (formerly DEP), which links a device's serial number to an MDM server through Apple Business Manager (ABM). When powered on, devices query Apple's activation servers to determine their assigned MDM service and automatically enroll. For macOS 14 and later, if devices don't enroll during first setup, they display a full-screen setup experience that enforces enrollment, preventing users from bypassing organizational control. +The workflow is enabled by Apple's Automated Device Enrollment (formerly DEP), which links a device's serial number to an MDM server through Apple Business (AB). When powered on, devices query Apple's activation servers to determine their assigned MDM service and automatically enroll. For macOS 14 and later, if devices don't enroll during first setup, they display a full-screen setup experience that enforces enrollment, preventing users from bypassing organizational control. This automation eliminates the traditional imaging workflow where IT teams receive shipments, unbox devices, connect them to imaging stations, install base configurations, and then ship them to users. Instead, devices go directly from the vendor to employees, arriving ready for automated configuration and immediate use. @@ -26,13 +26,13 @@ These provisioning, security, and efficiency improvements compound when managing ## How zero-touch deployment works -Mac zero-touch deployment operates through a three-tier architecture: Apple Business Manager as the enrollment authority, the MDM server as the policy distributor, and the Mac itself as an active participant in provisioning. +Mac zero-touch deployment operates through a three-tier architecture: Apple Business as the enrollment authority, the MDM server as the policy distributor, and the Mac itself as an active participant in provisioning. ### Device registration and assignment -Devices must be purchased from Apple or participating Apple Authorized Resellers to be automatically registered in Apple Business Manager. The vendor registers devices to your organization's Apple Business Manager account during purchase, linking each serial number to that organization. +Devices must be purchased from Apple or participating Apple Authorized Resellers to be automatically registered in Apple Business. The vendor registers devices to your organization's Apple Business account during purchase, linking each serial number to that organization. -After devices appear in Apple Business Manager, you assign them to the MDM server through the ABM web portal. This assignment links serial numbers with the MDM instance through a "virtual MDM server" configuration, establishing the trust relationship for automatic enrollment. +After devices appear in Apple Business, you assign them to the MDM server through the ABM web portal. This assignment links serial numbers with the MDM instance through a "virtual MDM server" configuration, establishing the trust relationship for automatic enrollment. ## Prerequisites and setup considerations @@ -40,9 +40,9 @@ Successfully implementing zero-touch deployment depends on having the right infr ### Required infrastructure -You need an Apple Business Manager account with organizational verification. Your organization must complete Apple's verification process before devices can enroll through ADE. This process requires a valid D-U-N-S number (an organization's business tax identification) and verification of organizational details by Apple representatives. Verification is separate from ABM account creation and typically takes 24-48 hours to complete. Missing this step is a common cause of ADE enrollment failures, as devices won't appear in your ABM account until verification is approved. +You need an Apple Business account with organizational verification. Your organization must complete Apple's verification process before devices can enroll through ADE. This process requires a valid D-U-N-S number (an organization's business tax identification) and verification of organizational details by Apple representatives. Verification is separate from ABM account creation and typically takes 24-48 hours to complete. Missing this step is a common cause of ADE enrollment failures, as devices won't appear in your ABM account until verification is approved. -Your MDM server must be added to Apple Business Manager as a virtual MDM server, establishing the trust relationship for device assignments. Your MDM tool must support Automated Device Enrollment with mandatory, non-removable enrollment profiles and the Auto Advance key for Setup Assistant customization. +Your MDM server must be added to Apple Business as a virtual MDM server, establishing the trust relationship for device assignments. Your MDM tool must support Automated Device Enrollment with mandatory, non-removable enrollment profiles and the Auto Advance key for Setup Assistant customization. Network connectivity requires internet access to contact Apple's activation servers and MDM endpoints during first boot. Fully automated deployment without any user interaction requires Ethernet connectivity during Auto Advance. Wi-Fi-only deployments typically require users to select the network during Setup Assistant, though Wi-Fi profiles can be pre-configured in enrollment settings. @@ -66,9 +66,9 @@ Apple announced that macOS 26 will expand DDM capabilities to include package de Platform SSO allows identity-first provisioning where authentication happens during enrollment rather than after. Platform SSO can now be activated during automated device enrollment, allowing employees to immediately access managed apps and company services without additional sign-ins. This addresses a common friction point where users complete device enrollment but then face repeated authentication prompts when accessing corporate resources. -### Apple Business Manager API capabilities +### Apple Business API capabilities -Apple Business Manager has received significant API enhancements that allow programmatic device management. New endpoints let administrators retrieve device management service information, list all devices assigned to a specific MDM server, and programmatically assign or unassign devices from management services. +Apple Business has received significant API enhancements that allow programmatic device management. New endpoints let administrators retrieve device management service information, list all devices assigned to a specific MDM server, and programmatically assign or unassign devices from management services. These new APIs support infrastructure-as-code patterns where device assignments and MDM configurations are version-controlled and deployed through automated pipelines, aligning with emerging GitOps-based management approaches for enterprise Mac fleet management. @@ -84,7 +84,7 @@ Autopilot depends on specific features available in Windows client, cloud identi | Platform | Zero-Touch Approach | Key Requirements | Enrollment Method | | ----- | ----- | ----- | ----- | -| macOS | Automated Device Enrollment (ADE) | Apple Business Manager, participating vendors | Cloud-based automatic enrollment via Setup Assistant | +| macOS | Automated Device Enrollment (ADE) | Apple Business, participating vendors | Cloud-based automatic enrollment via Setup Assistant | | Windows | Windows Autopilot | Cloud identity services, Windows MDM, participating OEMs | Cloud-based device registration and provisioning | | Linux | Custom automation | Configuration management tools, IT infrastructure | No standardized vendor-provided protocol | @@ -92,7 +92,7 @@ While Linux supports automated provisioning through tools like cloud-init, Ansib ### Post-enrollment management convergence -Though each operating system platform requires separate enrollment infrastructure (Apple Business Manager for macOS, Windows Autopilot for Windows, and custom automation for Linux) modern MDM solutions can provide unified management after enrollment completes. Administrators can configure management once and deploy across platforms, with MDM translating intent into platform-specific implementations. +Though each operating system platform requires separate enrollment infrastructure (Apple Business for macOS, Windows Autopilot for Windows, and custom automation for Linux) modern MDM solutions can provide unified management after enrollment completes. Administrators can configure management once and deploy across platforms, with MDM translating intent into platform-specific implementations. With single-platform device management solutions, IT teams must architect separate enrollment strategies per platform while seeking unified visibility and control post-enrollment. A practical approach involves accepting platform-specific enrollment workflows while standardizing on security baselines and compliance monitoring that work across operating systems. @@ -108,17 +108,17 @@ With Fleet GitOps, organizations define configuration through YAML files that sp Implementing zero-touch deployment gives your team consistent device provisioning while reducing manual workload. The right tool makes the difference between automation that works and automation that creates new problems. This is where Fleet comes in. -Fleet integrates with Apple Business Manager for automated device enrollment and provides the multi-platform visibility you need when managing mixed Mac, Windows, and Linux fleets. [Schedule a demo](https://fleetdm.com/contact) to see how Fleet simplifies Mac fleet management. +Fleet integrates with Apple Business for automated device enrollment and provides the multi-platform visibility you need when managing mixed Mac, Windows, and Linux fleets. [Schedule a demo](https://fleetdm.com/contact) to see how Fleet simplifies Mac fleet management. ## Frequently asked questions -### Can we implement zero-touch deployment without Apple Business Manager? +### Can we implement zero-touch deployment without Apple Business? -Automated Device Enrollment requires devices registered in Apple Business Manager or Apple School Manager, which is only possible when purchased from Apple or participating Apple Authorized Resellers. Alternative methods like user-initiated enrollment or Apple Configurator require manual steps and don't provide the same capabilities. Devices acquired through unauthorized channels can't use Automated Device Enrollment. +Automated Device Enrollment requires devices registered in Apple Business or Apple School Manager, which is only possible when purchased from Apple or participating Apple Authorized Resellers. Alternative methods like user-initiated enrollment or Apple Configurator require manual steps and don't provide the same capabilities. Devices acquired through unauthorized channels can't use Automated Device Enrollment. ### What happens if a device fails to enroll during first boot? -Common failure causes include network connectivity issues, MDM server configuration errors, or device assignment problems. Troubleshooting involves checking MDM synchronization status, verifying device assignment in Apple Business Manager, and ensuring access to Apple's activation servers and MDM endpoints. +Common failure causes include network connectivity issues, MDM server configuration errors, or device assignment problems. Troubleshooting involves checking MDM synchronization status, verifying device assignment in Apple Business, and ensuring access to Apple's activation servers and MDM endpoints. ### How does zero-touch deployment affect device security and compliance? @@ -133,5 +133,5 @@ Yes. Replacement devices enroll automatically through the same workflow as new d - + diff --git a/articles/managing-macs-globally-apple-ecosystem-deployment-security.md b/articles/managing-macs-globally-apple-ecosystem-deployment-security.md index f412c9b9c3a..66ff677bd1f 100644 --- a/articles/managing-macs-globally-apple-ecosystem-deployment-security.md +++ b/articles/managing-macs-globally-apple-ecosystem-deployment-security.md @@ -4,7 +4,7 @@ This guide covers why global Mac management requires specialized approaches and ## What is Apple ecosystem management for global deployments? -Apple's deployment ecosystem operates differently than Windows. Where Windows relies on Active Directory and Group Policy for configuration, Mac management integrates Apple Business Manager for device registration, the Push Notification service for device management communication, configuration profiles for device and user settings, and the MDM (Mobile Device Management) protocol for remote administration. These components work together through Apple's cloud infrastructure. +Apple's deployment ecosystem operates differently than Windows. Where Windows relies on Active Directory and Group Policy for configuration, Mac management integrates Apple Business for device registration, the Push Notification service for device management communication, configuration profiles for device and user settings, and the MDM (Mobile Device Management) protocol for remote administration. These components work together through Apple's cloud infrastructure. When you're managing hundreds to thousands of Mac devices across geographic regions, this architecture requires specific capabilities like automated enrollment systems that provision devices without physical access, federated identity management that connects devices to organizational accounts, standardized configuration deployment that maintains consistency, and continuous compliance monitoring that catches drift before audits. @@ -18,7 +18,7 @@ Organizations managing Mac devices across enterprise environments face several c * **Supporting employee choice and productivity:** Knowledge workers increasingly expect macOS as an option for development, design, and productivity workflows. * **Meeting security and compliance requirements:** Operating across multiple regions means facing overlapping regulatory requirements including GDPR, HIPAA, PCI-DSS, and jurisdiction-specific data residency rules. -* **Reducing management costs:** Zero-touch deployment through Apple Business Manager and Automated Device Enrollment can significantly reduce hands-on provisioning time. +* **Reducing management costs:** Zero-touch deployment through Apple Business and Automated Device Enrollment can significantly reduce hands-on provisioning time. * **Enabling distributed and remote workforces:** Devices ship directly to employee homes across multiple countries and may never connect to corporate network infrastructure. These capabilities work together through Apple's ecosystem rather than traditional Windows-based infrastructure, requiring specialized solutions that understand both Apple's architecture and enterprise requirements. @@ -27,21 +27,21 @@ These capabilities work together through Apple's ecosystem rather than tradition Enterprise Mac management operates through several interconnected technical components that work together to provide control across your global device fleet. -### Apple Business Manager +### Apple Business -Apple Business Manager (ABM) serves as the device registry to prove institutional ownership for automated enrollment and app distribution in enterprise deployments. When you purchase Mac devices through Apple or authorized resellers who participate in the Device Enrollment Program, device serial numbers automatically register to your organizational Apple Business Manager account. +Apple Business (AB) serves as the device registry to prove institutional ownership for automated enrollment and app distribution in enterprise deployments. When you purchase Mac devices through Apple or authorized resellers who participate in the Device Enrollment Program, device serial numbers automatically register to your organizational Apple Business account. -You assign devices in Apple Business Manager to specific MDM servers. This assignment tells Apple's activation servers which MDM server should manage each device. The system supports multiple tokens for organizations with different business units or for managed service providers supporting multiple clients. +You assign devices in Apple Business to specific MDM servers. This assignment tells Apple's activation servers which MDM server should manage each device. The system supports multiple tokens for organizations with different business units or for managed service providers supporting multiple clients. The practical usability of multiple tokens depends on your device management solution. Some solutions support multiple tokens but with interface limitations. Verify your device management solution vendor's multi-token capabilities before planning segmentation around multiple tokens. ### Automated Device Enrollment (ADE) -Automated Device Enrollment provisions devices globally without your IT team physically touching them. When a user powers on a device for the first time, it contacts Apple's activation servers during Setup Assistant, which recognize the device serial number, confirm its Apple Business Manager registration, and automatically downloads the assigned enrollment profile. +Automated Device Enrollment provisions devices globally without your IT team physically touching them. When a user powers on a device for the first time, it contacts Apple's activation servers during Setup Assistant, which recognize the device serial number, confirm its Apple Business registration, and automatically downloads the assigned enrollment profile. This wireless enrollment process means you can drop-ship devices directly to users anywhere in the world, with devices arriving at the desktop fully configured with required security settings and applications. -Supervision mode provides the highest level of management capabilities for ADE-enrolled devices. Unlike manually enrolled devices where users can remove MDM profiles, ADE-enrolled supervised Macs can enforce mandatory, immutable enrollment that persists across OS reinstallations because the device remains registered in Apple Business Manager. +Supervision mode provides the highest level of management capabilities for ADE-enrolled devices. Unlike manually enrolled devices where users can remove MDM profiles, ADE-enrolled supervised Macs can enforce mandatory, immutable enrollment that persists across OS reinstallations because the device remains registered in Apple Business. Your security policies remain enforced even if a user attempts to wipe and reinstall macOS. (Note: Manually supervised devices via Apple Configurator typically do not retain supervision after factory reset, though behavior can vary by workflow and macOS version.) @@ -69,7 +69,7 @@ Beyond the foundational Apple technologies, several operational components work ### Zero-touch deployment workflows -Zero-touch deployment represents the complete process from device purchase to productive end user without IT physically touching equipment. The workflow starts when you purchase devices through Apple Business Manager from participating suppliers, who automatically register serial numbers to your organization. You assign devices to users, and when users power on the device for the first time, it contacts Apple's activation servers and automatically downloads the enrollment profile, establishing supervised mode wirelessly. +Zero-touch deployment represents the complete process from device purchase to productive end user without IT physically touching equipment. The workflow starts when you purchase devices through Apple Business from participating suppliers, who automatically register serial numbers to your organization. You assign devices to users, and when users power on the device for the first time, it contacts Apple's activation servers and automatically downloads the enrollment profile, establishing supervised mode wirelessly. Enrollment can trigger app installation, scripts, and configurations that install during Setup Assistant, before the user sees the desktop. Users receive fully configured devices ready for work without IT intervention. This capability matters when you're deploying devices at scale to employees in regions without local IT support. @@ -81,7 +81,7 @@ Platform SSO on macOS Sequoia and later typically uses Secure Enclave-backed aut ### Software distribution and updates -Managing application installation and updates across global Mac fleets works better when using automated workflows that don't depend on users visiting App Store manually. Your MDM solution should manage application distribution through volume purchasing and automatic deployment. Apple Business Manager includes Apps and Books, which lets you purchase app licenses in bulk and assign them to device serial numbers rather than individual user accounts. +Managing application installation and updates across global Mac fleets works better when using automated workflows that don't depend on users visiting App Store manually. Your MDM solution should manage application distribution through volume purchasing and automatic deployment. Apple Business includes Apps and Books, which lets you purchase app licenses in bulk and assign them to device serial numbers rather than individual user accounts. Declarative Device Management provides automatic software update controls that install macOS updates during user-defined time windows. Devices check for updates independently, download them when network connectivity permits, and install them according to policies rather than waiting for MDM commands. This asynchronous behavior works better than traditional command-based updates for globally distributed fleets. @@ -127,15 +127,15 @@ What distinguishes multi-platform device management with osquery integration is ## Scaling Mac management with confidence -Managing Mac fleets across global regions requires architecture that handles Apple Business Manager enrollment, Declarative Device Management, and configuration verification beyond simple MDM command acknowledgment. Organizations need solutions that integrate with Apple's cloud infrastructure while supporting Windows and Linux devices from the same console. +Managing Mac fleets across global regions requires architecture that handles Apple Business enrollment, Declarative Device Management, and configuration verification beyond simple MDM command acknowledgment. Organizations need solutions that integrate with Apple's cloud infrastructure while supporting Windows and Linux devices from the same console. With Fleet, your team can manage Mac fleets alongside Windows and Linux devices from a single open-source solution, with osquery-based verification that confirms configurations actually exist on devices. [Schedule a demo](https://fleetdm.com/try-fleet/device-management) to see how Fleet fits your global device management strategy. ## Frequently asked questions -### What's the difference between MDM and Apple Business Manager? +### What's the difference between MDM and Apple Business? -Apple Business Manager is Apple's portal for automatically assigning devices to device management solutions during enrollment, linking device serial numbers to your organization and enabling Automated Device Enrollment (ADE). Device management is the management function plus the Apple MDM protocol and server software that configures and controls devices after they're enrolled. Both are needed: Apple Business Manager for zero-touch automated enrollment, and a device management solution to manage devices after enrollment. +Apple Business is Apple's portal for automatically assigning devices to device management solutions during enrollment, linking device serial numbers to your organization and enabling Automated Device Enrollment (ADE). Device management is the management function plus the Apple MDM protocol and server software that configures and controls devices after they're enrolled. Both are needed: Apple Business for zero-touch automated enrollment, and a device management solution to manage devices after enrollment. ### How many Macs can one admin realistically manage? diff --git a/articles/mdm-just-got-better.md b/articles/mdm-just-got-better.md index 79f732a6763..a0601ae33d0 100644 --- a/articles/mdm-just-got-better.md +++ b/articles/mdm-just-got-better.md @@ -18,11 +18,11 @@ This delivers the most frictionless macOS authentication experience to date — ## Managed device migration -You can now move macOS devices between MDM servers in Apple Business Manager or School Manager. No need to erase, rely on scripts, or use a vendor migration app. For iOS and iPadOS, MDM migration is also available without erasing devices. +You can now move macOS devices between MDM servers in Apple Business or School Manager. No need to erase, rely on scripts, or use a vendor migration app. For iOS and iPadOS, MDM migration is also available without erasing devices. Whether you’re switching providers, consolidating tools after an acquisition, or moving from cloud to on-prem (or vice versa), device migration is now native, scalable, and user-driven. -Apple Business Manager and Apple School Manager introduce: +Apple Business and Apple School Manager introduce: - Enforced migration deadlines with persistent user prompts - Full-screen modals or reboot requirements if migration is delayed @@ -60,7 +60,7 @@ These updates may be under the radar but they make a real difference: Apple’s WWDC25 updates point to a future of frictionless onboarding, declarative management, and user transparency. -**Fleet delivers that today**, supporting declarative MDM on macOS, iOS, and iPadOS, with zero-touch provisioning via Apple Business Manager and Windows Autopilot. +**Fleet delivers that today**, supporting declarative MDM on macOS, iOS, and iPadOS, with zero-touch provisioning via Apple Business and Windows Autopilot. Fleet lets you manage macOS, Windows, and Linux devices from one open, cross-platform system. It’s open source, scalable to millions of devices, and trusted by enterprises with 5,000+ endpoints. With Fleet Desktop, end users can see exactly what’s being managed and what data is collected—helping IT teams build trust through visibility and manage everything as code. diff --git a/articles/mdm-migration.md b/articles/mdm-migration.md index 14785613406..6585e9683e3 100644 --- a/articles/mdm-migration.md +++ b/articles/mdm-migration.md @@ -9,7 +9,7 @@ This guide provides instructions for migrating devices from your current MDM sol ## Requirements - A [deployed Fleet instance](https://fleetdm.com/docs/deploy/deploy-fleet) -- Fleet is connected to Apple Push Notification service (APNs) and Apple Business Manager (ABM). [See macOS MDM setup](https://fleetdm.com/guides/macos-mdm-setup) +- Fleet is connected to Apple Push Notification service (APNs) and Apple Business (AB). [See macOS MDM setup](https://fleetdm.com/guides/macos-mdm-setup) - For the end-user workflow: A service is required that can receive a webhook to send an unenroll request to the existing MDM server. See [this example](https://victoronsoftware.com/posts/webhook-flow-with-tines/) using Fleet webhooks with Tines. > **Important:** Apple MDM enrollment relies on a Safari-based system web view. If Safari is blocked or restricted, enrollment can fail. @@ -19,7 +19,7 @@ This guide provides instructions for migrating devices from your current MDM sol To migrate hosts, we will do the following steps: 1. Enroll hosts to Fleet -2. Assign hosts in Apple Business Manager (ABM) to Fleet +2. Assign hosts in Apple Business (AB) to Fleet 3. Choose migration workflow and migrate hosts ### Step 1: Enroll hosts to Fleet @@ -27,7 +27,7 @@ To migrate hosts, we will do the following steps: 1. First, [enroll your hosts](https://fleetdm.com/guides/enroll-hosts) to Fleet by installing Fleet's agent (fleetd). 2. Ensure your end users have access to an admin account on their Mac. End users won't be able to migrate on their own if they have a standard account. -### Step 2: Assign hosts in Apple Business Manager (ABM) to Fleet +### Step 2: Assign hosts in Apple Business (AB) to Fleet 1. In ABM, unassign your hosts from your current MDM solution by selecting **Devices** and then selecting **All Devices**. Then, select **Edit** next to **Edit MDM Server**, select **Unassign from the current MDM**, and select **Continue**. @@ -125,7 +125,7 @@ After turning on disk encryption in Fleet, share [these guided instructions](#ho In Fleet, the [Activation Lock](https://support.apple.com/en-us/HT208987) feature is disabled by default for automatically enrolled (ADE) hosts. -In 2024, Apple added the ability to manage activation lock in Apple Business Manager (ABM). For devices that are owned by the business and available in ABM, you can [turn off activation lock remotely](https://support.apple.com/en-ca/guide/apple-business-manager/axm812df1dd8/web). +In 2024, Apple added the ability to manage activation lock in Apple Business (AB). For devices that are owned by the business and available in ABM, you can [turn off activation lock remotely](https://support.apple.com/en-ca/guide/apple-business-manager/axm812df1dd8/web). If a device is not available in ABM and has Activation Lock enabled, we recommend asking the end user to follow these instructions to disable Activation Lock before migrating the device to Fleet: https://support.apple.com/en-us/HT208987. diff --git a/articles/mdm-providers-compared.md b/articles/mdm-providers-compared.md index ae7ff1ee8bc..3831d77b6da 100644 --- a/articles/mdm-providers-compared.md +++ b/articles/mdm-providers-compared.md @@ -20,7 +20,7 @@ Workspace ONE is an MDM product from Omnissa that provides unified endpoint mana ### Enrollment and provisioning -When new employees join or devices need to be deployed at scale, zero-touch enrollment lets IT ship devices directly to end users without manual setup. Fleet supports zero-touch deployment for macOS, Windows, and iOS/iPadOS, with Apple Business Manager integration for Apple devices and Windows Autopilot for Windows. Workspace ONE also supports zero-touch enrollment across these operating systems. +When new employees join or devices need to be deployed at scale, zero-touch enrollment lets IT ship devices directly to end users without manual setup. Fleet supports zero-touch deployment for macOS, Windows, and iOS/iPadOS, with Apple Business integration for Apple devices and Windows Autopilot for Windows. Workspace ONE also supports zero-touch enrollment across these operating systems. Both solutions provide options for preventing end users from removing management and MDM configuration profiles without authorization. Both also support MDM migration using Apple's native capabilities for macOS, iOS, and iPadOS. Fleet extends this further for Windows and Linux. Fleet offers migration scripts and documentation to help IT teams transition these devices with minimal end-user disruption, allowing teams to move enrolled devices to Fleet without requiring employees to re-enroll or lose data. @@ -71,7 +71,7 @@ Fleet's interoperable import/export format avoids vendor lock-in. Workspace ONE ## Deployment flexibility -Fleet offers both cloud-hosted and self-hosted deployment options with identical features and no restrictions. Self-hosted deployments enable organizations with strict data sovereignty requirements to keep all device data within their own infrastructure. Fleet manages all device types from a single console, with Apple Business Manager integration for zero-touch deployment on Apple devices. +Fleet offers both cloud-hosted and self-hosted deployment options with identical features and no restrictions. Self-hosted deployments enable organizations with strict data sovereignty requirements to keep all device data within their own infrastructure. Fleet manages all device types from a single console, with Apple Business integration for zero-touch deployment on Apple devices. Workspace ONE discourages on-premises deployment, steering organizations toward cloud hosting. @@ -87,7 +87,7 @@ Open-source tools like Fleet provide full transparency into the codebase, allowi #### How does Fleet manage Apple devices? -Fleet provides full Apple device management including MDM enrollment, configuration profiles, and software deployment for macOS, iOS, and iPadOS. Fleet supports Apple Business Manager integration for zero-touch deployment, and manages Apple devices alongside Windows, Linux, ChromeOS, and Android endpoints from a single console. +Fleet provides full Apple device management including MDM enrollment, configuration profiles, and software deployment for macOS, iOS, and iPadOS. Fleet supports Apple Business integration for zero-touch deployment, and manages Apple devices alongside Windows, Linux, ChromeOS, and Android endpoints from a single console. #### How does device reporting speed affect IT and security operations? diff --git a/articles/role-based-access.md b/articles/role-based-access.md index f1de8da3b5e..8cb50d41f5a 100644 --- a/articles/role-based-access.md +++ b/articles/role-based-access.md @@ -95,7 +95,7 @@ GitOps is an API-only and write-only role that can be used on CI/CD pipelines. | Retrieve contents from file carving | | | | | ✅ | | | Create Apple Push Certificates service (APNs) certificate signing request (CSR) | | | | | ✅ | | | View, edit, and delete APNs certificate | | | | | ✅ | | -| View, edit, and delete Apple Business Manager (ABM) connections | | | | | ✅ | | +| View, edit, and delete Apple Business (AB) connections | | | | | ✅ | | | View, edit, and delete Volume Purchasing Program (VPP) connections | | | | | ✅ | | | Connect Android Enterprise | | | | | ✅ | | | View disk encryption key for macOS, Windows, and Linux hosts | ✅ | ✅ | ✅ | ✅ | ✅ | | diff --git a/articles/setup-experience.md b/articles/setup-experience.md index 9447fac83ae..ab0b8232444 100644 --- a/articles/setup-experience.md +++ b/articles/setup-experience.md @@ -6,9 +6,9 @@ In Fleet, you can customize the out-of-the-box macOS, Windows, Linux, iOS, iPadO This guide covers macOS, iOS, iPadOS, and Android. Learn more about Windows and Linux in a [separate guide](https://fleetdm.com/guides/windows-linux-setup-experience). -macOS setup features require [connecting Fleet to Apple Business Manager (ABM)](https://fleetdm.com/guides/macos-mdm-setup#apple-business-manager-abm). +macOS setup features require [connecting Fleet to Apple Business (AB)](https://fleetdm.com/guides/macos-mdm-setup#apple-business-manager-abm). -> If a host is marked with a [migration deadline](https://support.apple.com/en-bh/guide/apple-business-manager/axm3a49a769d/web#axmf524b36d9) in Apple Business Manager, Fleet treats it as already set up. This means Fleet won’t install setup experience software, run scripts, or install bootstrap packages on that host. +> If a host is marked with a [migration deadline](https://support.apple.com/en-bh/guide/apple-business-manager/axm3a49a769d/web#axmf524b36d9) in Apple Business, Fleet treats it as already set up. This means Fleet won’t install setup experience software, run scripts, or install bootstrap packages on that host. Below is the end user experience for macOS. Check out the separate videos for [iOS](https://www.youtube.com/watch?v=bPtr3Qgp1JY), [iPadOS](https://www.youtube.com/watch?v=sK3ZR2iItJY), and [Android](https://www.youtube.com/watch?v=-zB1zgtGAMs). @@ -133,7 +133,7 @@ To sign the package we need a valid Developer ID Installer certificate: You can install software during first time macOS, iOS, iPadOS, Android, and [Windows and Linux setup](https://fleetdm.com/guides/windows-linux-setup-experience). -Currently, for macOS hosts, software is only installed on hosts that automatically enroll to Fleet via Apple Business Manager (ABM). For iOS and iPadOS hosts, software is only installed on hosts that enroll via ABM and hosts that manually enroll via the `/enroll` link (profile-based device enrollment). +Currently, for macOS hosts, software is only installed on hosts that automatically enroll to Fleet via Apple Business (AB). For iOS and iPadOS hosts, software is only installed on hosts that enroll via ABM and hosts that manually enroll via the `/enroll` link (profile-based device enrollment). Add setup experience software: @@ -239,13 +239,13 @@ To customize the Setup Assistant, we will do the following steps: ### Step 3: Test the custom Setup Assistant -Testing requires a test Mac that is present in your Apple Business Manager (ABM) account. We will wipe this Mac and use it to test the custom Setup Assistant. +Testing requires a test Mac that is present in your Apple Business (AB) account. We will wipe this Mac and use it to test the custom Setup Assistant. 1. Wipe the test Mac by selecting the Apple icon in top left corner of the screen, selecting **System Settings** or **System Preference**, and searching for "Erase all content and settings." Select **Erase All Content and Settings**. 2. In Fleet, navigate to the Hosts page and find your Mac. Make sure that the host's **MDM status** is set to "Pending." - > New Macs purchased through Apple Business Manager appear in Fleet with MDM status set to "Pending." See our [automatic enrollment guide](https://fleetdm.com/guides/macos-mdm-setup#apple-business-manager) for more information. + > New Macs purchased through Apple Business appear in Fleet with MDM status set to "Pending." See our [automatic enrollment guide](https://fleetdm.com/guides/macos-mdm-setup#apple-business-manager) for more information. 3. Transfer this host to a test fleet by selecting the checkbox to the left of the host and selecting **Transfer** at the top of the table. In the modal, choose the test fleet and select **Transfer**. diff --git a/articles/software-self-service.md b/articles/software-self-service.md index 1b46e4f1227..3481122ca2d 100644 --- a/articles/software-self-service.md +++ b/articles/software-self-service.md @@ -4,27 +4,11 @@ _Available in Fleet Premium_ Fleet’s self-service lets end users update and install approved apps and run scripts from a curated list on the **Fleet Desktop > Self-service** page. This reduces overhead for IT and keeps teams productive. -## Platforms +For macOS, Windows, and Linux hosts, self-service is accessible via the **Self-service** page in [Fleet Desktop](https://fleetdm.com/guides/fleet-desktop). -Fleet supports self-service software installs on the following platforms: +> **Note:** The **Self-service** page is hidden by default to avoid confusion in organizations that use a different self-service tool. It appears after you add self-service software or scripts. -macOS: - -- Custom packages (.pkg, .sh) -- Fleet-maintained apps -- App Store apps - -Windows: - -- Custom packages (.msi, .exe, .ps1) - -Linux: - -- Custom packages (.deb, .rpm, .sh, .tar.gz) - -iOS/iPadOS: - -- App Store apps and custom .ipa packages +For iOS/iPadOS hosts, [deploy a webclip](#deploy-self-service-on-ios-and-ipados) to give end users access. For Android hosts, all self-service software is available in the Managed Google Play store. [Learn more](https://fleetdm.com/guides/install-app-store-apps#google-play-android2). ## Add software diff --git a/articles/sysadmin-diaries-device-enrollment.md b/articles/sysadmin-diaries-device-enrollment.md index 733758a7e52..eefc3f0c346 100644 --- a/articles/sysadmin-diaries-device-enrollment.md +++ b/articles/sysadmin-diaries-device-enrollment.md @@ -14,7 +14,7 @@ Automatic Device Enrollment, often called DEP, empowers sysadmins to seamlessly Bring Your Own Device enrollment is intended to allow users to enroll their personal devices into corporate management systems. While BYOD fosters user convenience and productivity, it introduces potential security vulnerabilities. Notably, the ability for users to unenroll their devices poses a significant challenge for sysadmins, as it compromises centralized device management and security measures. -Our examination of BYOD enrollment underscores the importance of vigilance and proactive measures. As sysadmins, it is crucial to verify that all devices are appropriately registered within the Apple Business Manager (ABM) account. Devices not present in ABM should be [manually added](https://support.apple.com/guide/apple-business-manager/add-devices-from-apple-configurator-axm200a54d59/web) to ensure comprehensive device oversight and security. +Our examination of BYOD enrollment underscores the importance of vigilance and proactive measures. As sysadmins, it is crucial to verify that all devices are appropriately registered within the Apple Business (AB) account. Devices not present in AB should be [manually added](https://support.apple.com/guide/apple-business-manager/add-devices-from-apple-configurator-axm200a54d59/web) to ensure comprehensive device oversight and security. ## Differences and considerations diff --git a/articles/tales-from-fleet-security-securing-the-startup.md b/articles/tales-from-fleet-security-securing-the-startup.md index 92a7b0d2a12..4a432bf96c2 100644 --- a/articles/tales-from-fleet-security-securing-the-startup.md +++ b/articles/tales-from-fleet-security-securing-the-startup.md @@ -57,7 +57,7 @@ Google should offer more granularity than on/off for third-party cookies, such a ### ADE in other countries -First, we enrolled in ADE in the US. Once we had our customer numbers and Mobile Device Management (MDM) system linked up, we were ready to buy laptops in the US that would get configured out of the box. Then, we found a workaround for Canada. If you add Apple’s Reseller ID to [Apple Business Manager](https://business.apple.com/), you can order computers over the phone and have them linked to your business account. The Reseller ID part is critical. I learned that the hard way, by receiving a laptop ordered like this to find it not part of ADE. Fortunately, it was easy for me to [add it to ADE manually](https://support.apple.com/en-ca/guide/apple-configurator/welcome/ios). +First, we enrolled in ADE in the US. Once we had our customer numbers and Mobile Device Management (MDM) system linked up, we were ready to buy laptops in the US that would get configured out of the box. Then, we found a workaround for Canada. If you add Apple’s Reseller ID to [Apple Business](https://business.apple.com/), you can order computers over the phone and have them linked to your business account. The Reseller ID part is critical. I learned that the hard way, by receiving a laptop ordered like this to find it not part of ADE. Fortunately, it was easy for me to [add it to ADE manually](https://support.apple.com/en-ca/guide/apple-configurator/welcome/ios). We will keep trying the same approach in every country where we need Macs, though we know it will not be possible everywhere. We will either obtain equipment from a nearby country or rely on manual MDM enrollment by end-users for those countries. diff --git a/articles/technology-platform.md b/articles/technology-platform.md index f7b8b5c3afc..e5ef42d3448 100644 --- a/articles/technology-platform.md +++ b/articles/technology-platform.md @@ -12,7 +12,7 @@ As the fleet grows, the team needs a more scalable way to manage devices using a * **Devices managed:** ~15,000 iPads plus corporate macOS devices -* **Primary requirements:** GitOps workflows, API-first management, Apple Business Manager integration +* **Primary requirements:** GitOps workflows, API-first management, Apple Business integration * **Previous challenge:** Manual enrollment processes and limited automation @@ -33,7 +33,7 @@ Fleet must meet three key requirements: 1. **GitOps workflows** Integrate with GitHub Enterprise for version-controlled device management. -2. **Apple Business Manager integration** +2. **Apple Business integration** Seamlessly manage large numbers of iPads. 3. **API-first management** @@ -47,7 +47,7 @@ Device configurations live in version-controlled repositories. Changes go throug Fleet’s API powers several automated workflows. For example, device names synchronize automatically with the company’s inventory system, ensuring records remain accurate without manual updates. -Fleet also integrates with Apple Business Manager to automate provisioning of new devices. +Fleet also integrates with Apple Business to automate provisioning of new devices. ### A flexible migration strategy diff --git a/articles/the-mdm-mirgration-reality.md b/articles/the-mdm-mirgration-reality.md index dc4aa0da7d9..5b7652e5e03 100644 --- a/articles/the-mdm-mirgration-reality.md +++ b/articles/the-mdm-mirgration-reality.md @@ -1,6 +1,6 @@ # The MDM migration reality: easier, but not easy -Recent macOS and iOS/iPadOS updates, along with improvements in Apple Business Manager (ABM), have made MDM migration less disruptive. Previously, migrating iOS and iPadOS devices to a new MDM server required a complete factory reset, disrupting end users. Now, these mobile devices can be reassigned to a new MDM server without wiping, bringing them in line with macOS devices which already supported non-destructive migration. +Recent macOS and iOS/iPadOS updates, along with improvements in Apple Business (AB), have made MDM migration less disruptive. Previously, migrating iOS and iPadOS devices to a new MDM server required a complete factory reset, disrupting end users. Now, these mobile devices can be reassigned to a new MDM server without wiping, bringing them in line with macOS devices which already supported non-destructive migration. While macOS avoided the factory reset requirement, migration prior to macOS 26 still required careful coordination and communication with end users and, in some cases, custom workflows to ease the transition. diff --git a/articles/what-is-apple-business-manager-a-complete-guide.md b/articles/what-is-apple-business-manager-a-complete-guide.md index 2c4861ad643..f75860577fa 100644 --- a/articles/what-is-apple-business-manager-a-complete-guide.md +++ b/articles/what-is-apple-business-manager-a-complete-guide.md @@ -1,20 +1,20 @@ -# What is Apple Business Manager? A complete guide +# What is Apple Business? A complete guide -This article explains what Apple Business Manager (ABM) does and its key features. +This article explains what Apple Business (AB) does and its key features. -## Apple Business Manager defined +## Apple Business defined -Apple Business Manager (ABM) is Apple's free service for tracking the provenance of an organization's purchased devices from Apple or from authorized Apple resellers. By validating institutional ownership of Apple devices, ABM allows organizations to: +Apple Business (AB) is Apple's free service for tracking the provenance of an organization's purchased devices from Apple or from authorized Apple resellers. By validating institutional ownership of Apple devices, AB allows organizations to: -- Connect their MDM servers to ABM to enable Automated Device Enrollment (ADE) for zero-touch enrollment workflows +- Connect their MDM servers to AB to enable Automated Device Enrollment (ADE) for zero-touch enrollment workflows - Control licensed software and content distribution via Apps and Books management - Administer Managed Apple Accounts -The backend of the ABM infrastructure handles connecting institutionally-owned devices to Apple activation servers after first boot. Devices negotiate with ABM and become associated to an organization's MDM server to receive an enrollment profile. When a device is enrolled, users are walked through a partially or fully automated Setup Assistant process, usually followed by a customized provisioning workflow. The "Out Of the Box" (OOB) experience for a new employee is easy to understand and hassle-free, resulting in a completely configured, fully-managed device that is ready for work without manual or IT intervention. +The backend of the AB infrastructure handles connecting institutionally-owned devices to Apple activation servers after first boot. Devices negotiate with AB and become associated to an organization's MDM server to receive an enrollment profile. When a device is enrolled, users are walked through a partially or fully automated Setup Assistant process, usually followed by a customized provisioning workflow. The "Out Of the Box" (OOB) experience for a new employee is easy to understand and hassle-free, resulting in a completely configured, fully-managed device that is ready for work without manual or IT intervention. -Apple consolidated ABM in 2018 from two previously separate programs: the Device Enrollment Program (DEP) for automated enrollment and the Volume Purchase Program (VPP) for app licensing. The consolidation eliminated operational silos of managing device enrollment in one system and app distribution in another. +Apple consolidated AB in 2018 from two previously separate programs: the Device Enrollment Program (DEP) for automated enrollment and the Volume Purchase Program (VPP) for app licensing. The consolidation eliminated operational silos of managing device enrollment in one system and app distribution in another. -ABM is a single-portal for: +AB is a single-portal for: - Device enrollment automation (ADE) - Software and content purchasing (Apps and Books) @@ -22,21 +22,21 @@ ABM is a single-portal for: integrated with your chosen mobile device management (MDM) solution for complete control of your devices across the Apple platform. -## Is Apple Business Manager an MDM? +## Is Apple Business an MDM? -ABM alone is not a substitute for an MDM solution. MDM servers connected to ABM are responsible for performing management actions on devices after enrollment. +AB alone is not a substitute for an MDM solution. MDM servers connected to AB are responsible for performing management actions on devices after enrollment. -Pairing ABM with an MDM solution results in a comprehensive management system where automated enrollment feeds devices to the MDM server. The MDM server deploys MDM commands and configuration profiles to enforce settings and controls post-enrollment. +Pairing AB with an MDM solution results in a comprehensive management system where automated enrollment feeds devices to the MDM server. The MDM server deploys MDM commands and configuration profiles to enforce settings and controls post-enrollment. -MDM is possible without ABM, but, manual enrollment can create bottlenecks that slow provisioning and increase IT overhead. ABM enables ADE which allows for Apple devices to be fully managed and supervised, giving organizations access to the full range of Apple device management capabilities. +MDM is possible without AB, but, manual enrollment can create bottlenecks that slow provisioning and increase IT overhead. AB enables ADE which allows for Apple devices to be fully managed and supervised, giving organizations access to the full range of Apple device management capabilities. -ABM can be integrated with all major MDM solutions, including [Fleet](http://fleetdm.com/). This flexibility allows organizations to evaluate MDM vendors based on specific requirements or features like REST API capabilities, cross-platform support, data collection, security compliance, remediation capabilities, GitOps automation, and self-hosting options. +AB can be integrated with all major MDM solutions, including [Fleet](http://fleetdm.com/). This flexibility allows organizations to evaluate MDM vendors based on specific requirements or features like REST API capabilities, cross-platform support, data collection, security compliance, remediation capabilities, GitOps automation, and self-hosting options. -If your current MDM fails to meet your needs, you can switch MDM vendors without having to create a new ABM instance. At WWDC 2025 Apple introduced [Managed Device Migration](https://fleetdm.com/announcements/mdm-just-got-better) making the move from your current MDM vendor to any other easier than ever. +If your current MDM fails to meet your needs, you can switch MDM vendors without having to create a new AB instance. At WWDC 2025 Apple introduced [Managed Device Migration](https://fleetdm.com/announcements/mdm-just-got-better) making the move from your current MDM vendor to any other easier than ever. ### What is Apple Business Essentials? -Apple Business Essentials (ABE) is Apple's MDM solution for small businesses that bundles enrollment and settings enforcement into a single paid subscription ($2.99 to $24.99 per device per month). Unlike ABM which requires a separate MDM, ABE packages ABM functionality with built-in MDM, 24/7 support, and iCloud storage in a simplified offering. +Apple Business Essentials (ABE) is Apple's MDM solution for small businesses that bundles enrollment and settings enforcement into a single paid subscription ($2.99 to $24.99 per device per month). Unlike AB which requires a separate MDM, ABE packages AB functionality with built-in MDM, 24/7 support, and iCloud storage in a simplified offering. ABE works best for organizations with specific characteristics and constraints: @@ -48,11 +48,11 @@ ABE works best for organizations with specific characteristics and constraints: ABE lacks advanced controls like conditional access, dynamic grouping, and sophisticated automation, while app deployment is via App Store software distribution custom package installation capabilities. -Complex organizations with strict management requirements should consider using ABM paired with a a third-party MDM solution for greater flexibility and capabilities. +Complex organizations with strict management requirements should consider using AB paired with a a third-party MDM solution for greater flexibility and capabilities. -## What are the key features of Apple Business Manager? +## What are the key features of Apple Business? -ABM has three core capabilities that work together to automate device provisioning at scale: Automated Device Enrollment (ADE), volume purchasing for Apps and Books, and identity management through Managed Apple Accounts +AB has three core capabilities that work together to automate device provisioning at scale: Automated Device Enrollment (ADE), volume purchasing for Apps and Books, and identity management through Managed Apple Accounts ### Automated Device Enrollment @@ -60,67 +60,67 @@ Automated Device Enrollment (ADE) streamlines MDM enrollment by handling initial ### Volume purchasing and app distribution -ABM provides bulk app and content purchases with remote distribution that doesn't require employees to use personal Apple Accounts on-device. This gives you complete license management with remote deployment capabilities even if users or your organization has disabled the App Store on managed devices. +AB provides bulk app and content purchases with remote distribution that doesn't require employees to use personal Apple Accounts on-device. This gives you complete license management with remote deployment capabilities even if users or your organization has disabled the App Store on managed devices. Admins can push app updates and revoke compromised app access during security incidents across their entire fleet without requiring physical access to devices. -When employees leave, licenses are maintained by your organization rather than leaving with them. This means licenses are available for reassignment to current employees and licensing costs can be more easily managed. For organizations with proprietary software, ABM allows custom, in-house app distribution directly to managed devices without requiring App Store distribution or public availability. +When employees leave, licenses are maintained by your organization rather than leaving with them. This means licenses are available for reassignment to current employees and licensing costs can be more easily managed. For organizations with proprietary software, AB allows custom, in-house app distribution directly to managed devices without requiring App Store distribution or public availability. ### Managed Apple Accounts -Managed Apple Accounts allow organizations to separate work and personal identities. ABM People Managers can control all identities created within an organization's domain. This solves the problem of employees controlling Apple Accounts created with an organizational identity but intended for personal use outside the organization's control. +Managed Apple Accounts allow organizations to separate work and personal identities. AB People Managers can control all identities created within an organization's domain. This solves the problem of employees controlling Apple Accounts created with an organizational identity but intended for personal use outside the organization's control. -Managed Apple Accounts also enable role-based access control within ABM. This allows an organization to delegate specific ABM administrative responsibilities. A Content Manager, for example, can distribute apps without accessing device configurations. A People Manager can provision Managed Apple Accounts without access to change MDM assignments. +Managed Apple Accounts also enable role-based access control within AB. This allows an organization to delegate specific AB administrative responsibilities. A Content Manager, for example, can distribute apps without accessing device configurations. A People Manager can provision Managed Apple Accounts without access to change MDM assignments. -Role-based access control typically follows the security principle of "least privilege" while distributing workloads across your IT team, preventing any single ABM administrator from having unnecessary access to sensitive configurations. +Role-based access control typically follows the security principle of "least privilege" while distributing workloads across your IT team, preventing any single AB administrator from having unnecessary access to sensitive configurations. -## Benefits of Apple Business Manager +## Benefits of Apple Business -ABM eliminates manual device setup, reduces administrative overhead through automation, and provides vendor flexibility at zero platform cost. +AB eliminates manual device setup, reduces administrative overhead through automation, and provides vendor flexibility at zero platform cost. - **Deployment efficiency:** Automated enrollment delivers devices ready for work on first boot, allowing IT teams to shift their focus from repetitive device configuration to designing policies and maintaining infrastructure. -- **Operational scale:** ABM supports organizational growth without requiring architectural changes, keeping your provisioning process consistent as your device fleet expands from dozens to thousands of devices. +- **Operational scale:** AB supports organizational growth without requiring architectural changes, keeping your provisioning process consistent as your device fleet expands from dozens to thousands of devices. -- **Cost savings:** ABM itself costs nothing, and volume app purchasing keeps software and content license expenses predictable. +- **Cost savings:** AB itself costs nothing, and volume app purchasing keeps software and content license expenses predictable. -- **Security and compliance:** ABM enables good security posture at many different levels: +- **Security and compliance:** AB enables good security posture at many different levels: - Device supervision via ADE enforce security settings from first boot and enabling remote lock / wipe capabilities - Managed Apple Accounts can help to keep work data separate from personal information - - Role-based access controls in ABM allow organizations to engage in best practices + - Role-based access controls in AB allow organizations to engage in best practices -- **Vendor flexibility:** ABM integrates with any MDM solution, preventing vendor lock-in. Select the MDM solution that fits your organization bwest and switch MDM vendors without rebuilding your enrollment infrastructure via Managed Device Migration. +- **Vendor flexibility:** AB integrates with any MDM solution, preventing vendor lock-in. Select the MDM solution that fits your organization bwest and switch MDM vendors without rebuilding your enrollment infrastructure via Managed Device Migration. -## Who should use Apple Business Manager? +## Who should use Apple Business? -Small US-only teams with fewer than 500 employees and basic security needs might be able to use ABE. Organizations managing Apple devices at scale should use ABM paired with a third-party MDM solution, such as [Fleet](https://fleetdm.com/device-management). +Small US-only teams with fewer than 500 employees and basic security needs might be able to use ABE. Organizations managing Apple devices at scale should use AB paired with a third-party MDM solution, such as [Fleet](https://fleetdm.com/device-management). -Value emerges for enterprises with distributed teams, international operations, or those planning to exceed 500 employees. Large enterprises with multi-location operations will appreciate ABM's global availability and unlimited scale since Apple Business Essentials has strict size and geographic limits. +Value emerges for enterprises with distributed teams, international operations, or those planning to exceed 500 employees. Large enterprises with multi-location operations will appreciate AB's global availability and unlimited scale since Apple Business Essentials has strict size and geographic limits. -Fleet pairs well with ABM. Fleet's MDM features are built on top of [osquery](https://fleetdm.com/guides/osquery-a-tool-to-easily-ask-questions-about-operating-systems), Fleet provides deep endpoint visibility through 300+ queryable data tables and delivers device reporting in under 30 seconds. Its cross-platform support extends beyond the Apple ecosystem to Windows, Linux, Chromebooks and Android devices. For organizations with data residency requirements, Fleet offers both hosted, cloud-managed and self-hosted server deployment options, while native GitOps and API-first design integrate with the modern, infrastructure-as-code practices large enterprises are adopting to thrive. +Fleet pairs well with AB. Fleet's MDM features are built on top of [osquery](https://fleetdm.com/guides/osquery-a-tool-to-easily-ask-questions-about-operating-systems), Fleet provides deep endpoint visibility through 300+ queryable data tables and delivers device reporting in under 30 seconds. Its cross-platform support extends beyond the Apple ecosystem to Windows, Linux, Chromebooks and Android devices. For organizations with data residency requirements, Fleet offers both hosted, cloud-managed and self-hosted server deployment options, while native GitOps and API-first design integrate with the modern, infrastructure-as-code practices large enterprises are adopting to thrive. ## What about Apple devices in education and the public sector? -Educational institutions should use Apple School Manager (ASM) instead of ABM. ASM has all the features of ABM with additional features designed for K-12 and higher education like Shared iPad management, student information management tools, and student account provisioning. Schools don't need both portals and only need to pair ASM with a third-party MDM solution like [Fleet](http://fleetdm.com/). +Educational institutions should use Apple School Manager (ASM) instead of AB. ASM has all the features of AB with additional features designed for K-12 and higher education like Shared iPad management, student information management tools, and student account provisioning. Schools don't need both portals and only need to pair ASM with a third-party MDM solution like [Fleet](http://fleetdm.com/). -ABM works with all MDM solutions and provides detailed procurement, enrollment and compliance data. Government and public sector agencies managing Apple devices that: +AB works with all MDM solutions and provides detailed procurement, enrollment and compliance data. Government and public sector agencies managing Apple devices that: Must meet strict vendor flexibility and audit requirements Operate under strict procurement and regulatory frameworks -should require ABM as part of their technology stack. +should require AB as part of their technology stack. Fleet helps these organizations [meet compliance requirements](https://fleetdm.com/securing/get-and-stay-compliant-across-your-devices-with-fleet) through automated vulnerability detection, policy enforcement, continuous monitoring, and deployment flexibility with both cloud-hosted and self-hosted options that address data residency requirements. -## Pairing ABM with the right MDM +## Pairing AB with the right MDM -ABM provides the enrollment infrastructure that makes automated Apple device provisioning possible. Pairing ABM's free platform with your chosen MDM solution eliminates manual device setup and gives you a flexible foundation that scales with your organization. +AB provides the enrollment infrastructure that makes automated Apple device provisioning possible. Pairing AB's free platform with your chosen MDM solution eliminates manual device setup and gives you a flexible foundation that scales with your organization. -For comprehensive device management across Mac, iPhone, iPad, Windows, and Linux, Fleet provides open-source MDM that integrates with ABM. Once ABM handles enrollment, Fleet manages your devices with an API-first architecture that supports GitOps workflows and configuration as code. [Schedule a Fleet demo](https://fleetdm.com/contact) to explore how ABM and Fleet work together. +For comprehensive device management across Mac, iPhone, iPad, Windows, and Linux, Fleet provides open-source MDM that integrates with AB. Once AB handles enrollment, Fleet manages your devices with an API-first architecture that supports GitOps workflows and configuration as code. [Schedule a Fleet demo](https://fleetdm.com/contact) to explore how AB and Fleet work together. - + - + diff --git a/articles/what-is-apple-mdm.md b/articles/what-is-apple-mdm.md index 77316dbda62..aaed2a89f83 100644 --- a/articles/what-is-apple-mdm.md +++ b/articles/what-is-apple-mdm.md @@ -1,6 +1,6 @@ # Apple MDM: A complete guide -Managing Apple devices across an enterprise organization requires more than just deploying hardware. Configuration settings, security policies, and app distribution must reach hundreds or thousands of macOS, iOS, and iPadOS devices without manual intervention. Apple's Mobile Device Management (MDM) protocol provides the foundation for managing large device fleets, but the protocol itself is just one piece of the puzzle. This guide covers how Apple MDM works, integration with Apple Business Manager (ABM). +Managing Apple devices across an enterprise organization requires more than just deploying hardware. Configuration settings, security policies, and app distribution must reach hundreds or thousands of macOS, iOS, and iPadOS devices without manual intervention. Apple's Mobile Device Management (MDM) protocol provides the foundation for managing large device fleets, but the protocol itself is just one piece of the puzzle. This guide covers how Apple MDM works, integration with Apple Business (AB). ## What is Apple MDM and how does it work? @@ -10,19 +10,19 @@ The architecture relies on two core components working together. A check-in prot When administrators push a configuration change, the MDM server doesn't communicate directly with the device. Instead, it sends a push notification through APNs, which triggers the device to check in with the MDM server and retrieve any queued commands. This communication depends on valid certificates, including an APNs certificate that requires annual renewal to keep your fleet connected. -## Managing enrollment and apps through Apple Business Manager +## Managing enrollment and apps through Apple Business -Without Apple Business Manager (ABM), enrollment is typically manual or user-initiated, often via profile installation or account-driven enrollment flows. These approaches work but are harder to scale than zero-touch deployment. +Without Apple Business (AB), enrollment is typically manual or user-initiated, often via profile installation or account-driven enrollment flows. These approaches work but are harder to scale than zero-touch deployment. -ABM connects Apple's activation servers to your MDM server. When you purchase devices through Apple or authorized resellers, they automatically appear in your ABM account. From there, you assign devices to your MDM server so they enroll automatically when employees power them on for the first time. +AB connects Apple's activation servers to your MDM server. When you purchase devices through Apple or authorized resellers, they automatically appear in your AB account. From there, you assign devices to your MDM server so they enroll automatically when employees power them on for the first time. -ABM also centralizes app purchasing through Apps and Books, letting you buy apps in bulk and distribute them to devices without requiring individual Apple IDs. Apple School Manager (ASM) provides the same capabilities for educational institutions. +AB also centralizes app purchasing through Apps and Books, letting you buy apps in bulk and distribute them to devices without requiring individual Apple IDs. Apple School Manager (ASM) provides the same capabilities for educational institutions. ### Zero-touch deployment through automated device enrollment Automated Device Enrollment (ADE) lets employees power on a new Mac or iPhone and start working without IT touching the device. The device automatically enrolls in your MDM server during Setup Assistant, receives its configuration profiles, and installs required apps. -Here's how it works: when an employee powers on a new device, it contacts Apple's activation servers, which recognize the device belongs to your organization through ABM. Apple redirects the device to your MDM server, and enrollment happens automatically. Depending on configuration (for example, Auto Advance on supported Macs), setup can be largely hands-off. +Here's how it works: when an employee powers on a new device, it contacts Apple's activation servers, which recognize the device belongs to your organization through AB. Apple redirects the device to your MDM server, and enrollment happens automatically. Depending on configuration (for example, Auto Advance on supported Macs), setup can be largely hands-off. ADE provides capabilities that manual enrollment can't match: @@ -64,7 +64,7 @@ DDM coexists with traditional MDM commands and profiles, so you can adopt it gra Most enterprises manage more than just Apple devices. IT teams typically oversee fleets spanning macOS, Windows, and Linux and more. This historically has meant running separate management tools for each platform. Multi-platform MDM tools address this fragmentation by managing all devices through a single console. -The best multi-platform tools don't sacrifice Apple-specific capabilities for multi-platform coverage. They implement Apple's MDM protocol natively, including full support for ABM integration, ADE, Apps and Books, and declarative device management, while extending the same depth of management to Windows and Linux devices. +The best multi-platform tools don't sacrifice Apple-specific capabilities for multi-platform coverage. They implement Apple's MDM protocol natively, including full support for AB integration, ADE, Apps and Books, and declarative device management, while extending the same depth of management to Windows and Linux devices. ### When Apple-only MDM falls short @@ -78,7 +78,7 @@ Linux typically uses configuration management tools like Ansible or Puppet with When evaluating tools that manage Apple devices alongside other platforms, certain capabilities separate tools that genuinely simplify management from those that just add another layer of abstraction: -* **Native Apple MDM support:** The tool should implement Apple's MDM protocol properly, including ABM integration, ADE, Apps and Books, and configuration profiles. +* **Native Apple MDM support:** The tool should implement Apple's MDM protocol properly, including AB integration, ADE, Apps and Books, and configuration profiles. * **Declarative device management:** Support for DDM helps ensure you can take advantage of Apple's modern management architecture. * [**GitOps workflows:**](https://fleetdm.com/gitops-workshop) Infrastructure-as-code approaches let you version control configurations and maintain audit trails. * **API-first architecture:** Robust APIs enable [automation workflows](https://fleetdm.com/guides/automations) and integration with your existing security and IT tools. @@ -88,15 +88,15 @@ Open-source options add transparency to the equation. Organizations can inspect ## Manage Apple devices across your fleet -Apple MDM provides the protocol foundation for enterprise device management, while ABM and automated device enrollment enable zero-touch deployment workflows. Declarative device management points toward Apple's intended direction for modern management. +Apple MDM provides the protocol foundation for enterprise device management, while AB and automated device enrollment enable zero-touch deployment workflows. Declarative device management points toward Apple's intended direction for modern management. -For comprehensive device management across Mac, iPhone, iPad, Windows, and Linux, Fleet provides open-core MDM that integrates with ABM. Fleet manages your devices with an API-first architecture that supports GitOps workflows and configuration as code. [Try Fleet](https://fleetdm.com/try-fleet) to see how unified device management works across your entire fleet. +For comprehensive device management across Mac, iPhone, iPad, Windows, and Linux, Fleet provides open-core MDM that integrates with AB. Fleet manages your devices with an API-first architecture that supports GitOps workflows and configuration as code. [Try Fleet](https://fleetdm.com/try-fleet) to see how unified device management works across your entire fleet. ## Frequently asked questions -### What's the difference between MDM and ABM? +### What's the difference between MDM and AB? -MDM is the protocol and server infrastructure that actually manages devices, pushing configurations, enforcing policies, and executing commands. ABM is Apple's web portal for device enrollment and app purchasing. ABM connects to your MDM server and tells Apple's activation servers which MDM server should manage each device. You need both working together for automated enrollment and zero-touch deployment. +MDM is the protocol and server infrastructure that actually manages devices, pushing configurations, enforcing policies, and executing commands. AB is Apple's web portal for device enrollment and app purchasing. AB connects to your MDM server and tells Apple's activation servers which MDM server should manage each device. You need both working together for automated enrollment and zero-touch deployment. ### Can users remove MDM profiles from their devices? @@ -104,7 +104,7 @@ It depends on the enrollment method. Devices enrolled through Automated Device E ### How long does it take to set up Apple MDM for an organization? -Initial setup often takes anywhere from a few days to a couple of weeks, depending on your existing infrastructure. You'll need to establish an ABM account, obtain APNs certificates, connect your MDM server, and configure enrollment profiles. Fleet's [MDM setup guide](https://fleetdm.com/guides/macos-mdm-setup) walks through the specific steps for connecting ABM. +Initial setup often takes anywhere from a few days to a couple of weeks, depending on your existing infrastructure. You'll need to establish an AB account, obtain APNs certificates, connect your MDM server, and configure enrollment profiles. Fleet's [MDM setup guide](https://fleetdm.com/guides/macos-mdm-setup) walks through the specific steps for connecting AB. ### Does Apple MDM work for BYOD scenarios? diff --git a/articles/what-is-application-management.md b/articles/what-is-application-management.md index 18d24d24bc0..e3f12912c58 100644 --- a/articles/what-is-application-management.md +++ b/articles/what-is-application-management.md @@ -126,7 +126,7 @@ Your organization's specific requirements should determine which approach works ### Platform-specific MDM with application management -An Apple-focused MDM platform like Jamf Pro includes application management. It is focused on Apple devices with functions like Apple Business Manager integration, Apps and Books license management and managed app deployments, but, it only supports Apple devices. +An Apple-focused MDM platform like Jamf Pro includes application management. It is focused on Apple devices with functions like Apple Business integration, Apps and Books license management and managed app deployments, but, it only supports Apple devices. Organizations with heterogeneous environments that include multiple device platforms (e.g., Apple, Linux, Windows, Chromebook, iOS / iPadOS, Android) require multiple management solutions, or, cross-platform managements solutions. diff --git a/articles/windows-mdm-setup.md b/articles/windows-mdm-setup.md index 924dbdb9522..0acbb78c521 100644 --- a/articles/windows-mdm-setup.md +++ b/articles/windows-mdm-setup.md @@ -49,13 +49,18 @@ With Windows MDM turned on, enroll a Windows host to Fleet by installing [Fleet' ### Migrating from another MDM solution -When migrating Windows hosts from another MDM, devices may fail to report MDM as "On." You might see enrollment errors (e.g., ⁠400 or ⁠0x8018000a) in [fleetd logs](https://fleetdm.com/guides/enroll-hosts#debugging). +When migrating Windows hosts from another MDM, devices may fail to report MDM as "On." You might see enrollment errors (e.g., 400 or 0x8018000a) in [fleetd logs](https://fleetdm.com/guides/enroll-hosts#debugging). Local accounts can also become locked. -These issues are caused by residual enrollment data, registry conflicts, tattooed policies, or third-party management agents from the previous MDM solution. +These issues are usually caused by leftover enrollment data or third-party management agents from the previous MDM. -[Run the combined remediation script](https://fleetdm.com/guides/scripts#manually-run-scripts) below on the affected hosts, then **reboot the device** and select **Refetch** on the host details: +To fix this: + +1. Run the [fix-windows-mdm-migration.ps1](https://github.com/fleetdm/fleet/blob/main/docs/solutions/windows/scripts/fix-windows-mdm-migration.ps1) script on affected hosts. +2. Reboot the device. +3. In Fleet, open the host and select **Refetch** on the **Host details** page. + +Learn how to [run scripts in Fleet](https://fleetdm.com/guides/scripts#manually-run-scripts). -- [fix-windows-mdm-migration.ps1](https://github.com/fleetdm/fleet/blob/main/docs/solutions/windows/scripts/fix-windows-mdm-migration.ps1): Comprehensive remediation script that detects and fixes common post-migration issues. Each fix only runs if the problem is detected. The script handles: incorrect MDM enrollment flags, stale enrollment records and caches, broken Workplace Join configuration, unreachable WSUS server configuration, orphaned EnterpriseMgmt scheduled tasks, and local account lockout caused by tattooed `LocalUsersAndGroups` policies. **Conflicting RMM or management agents:** Third-party RMM agents (such as N-able/SolarWinds, ConnectWise, or Kaseya) installed alongside the previous MDM solution can interfere with Fleet's MDM enrollment and may cause Windows Update to stop functioning. Check for and remove any RMM agents that are no longer needed before or after migrating to Fleet.