Apple Mobile Device Management FAQ: your top questions answered

The world of Apple Mobile Device Management (MDM) can sometimes raise questions. Here are some of the most frequently asked questions, some answers, and some suggestions for further reading.

November 15 2024 by

Haddayr Copley-Woods

Illustration of mobile device management, showing employees at work in varying places and in varying ways.

What is Apple Mobile Device Management? What is Apple MDM?

Apple’s expansion in the enterprise has brought with it a more productive workforce and the ability for employees to truly work anywhere.

But more freedom, an expanding perimeter and a new operating system can offer challenges, as well.

Organizations of any size must keep everyone’s devices running optimally, ensure hardware and networks are protected at all times and provide the proper access to each employee: not too little, not too much.

To ensure speed, consistency and automation of security best practices, your organization will need an MDM.

What are the benefits of Apple MDM?

A good Apple MDM provides:

  • Remote device, inventory and app management
  • Visibility into device states and automated OS updates and patch management
  • Compliance with policies, configurations and updates without need for IT to touch a device

A great Apple MDM is purpose-built for all Apple devices.

It should manage everything, including:

  • iOS
  • iPadOS
  • watchOS
  • tvOS
  • macOS
  • visionOS

It should also offer a way for employees to download apps they need, when they need them: without any need to contact IT. The best Apple MDM integrates seamlessly with threat prevention and remediation solutions, allowing organizations to secure their networks and data while also protecting employee safety and privacy.

With a powerful MDM service such as Jamf Pro or Jamf Now managing your devices, your organization will provide better service to your employees, free up IT time and better manage risk. You’ll also be able to offer remote workers a better experience, create engaging and useful onboarding experiences and ensure a safer connection for all devices and users.

Frequently asked questions about Apple MDM

Q: Why is Apple and iOS MDM important for businesses?

Put simply, if you want your business to grow, you need an MDM. And if your employees use Apple devices, you need an MDM built specifically for Apple. The power of MDM is the ability to grow at scale: assigning and preloading devices with everything that new employees need before they even open the box, Smart Groups to manage many groups at once and the big picture of your organization's inventory. Lost or untracked devices are a drain on your organization, and those devices are often not updated to compliance standards and can create a security risk.

Q: What is device supervision?

Device supervision gives organizations more control over organization-issued iOS devices. Supervision allows Mac administrators to apply safety or data use restrictions. It also allows IT to automatically update apps and to push out configurations and features useful to everyone in a company.

>> Watch this video to learn about why device supervision is important for businesses.

Q: What is Apple Business Manager?

It's a simple, web-based portal for IT administrators to easily buy Apple devices in volume. Businesses can use Apple Business Manager as a database of their Apple device purchases as well as a database of App Store apps. With Apple Business Manager, your organization will not need an Apple ID for every individual, and each device you purchase through Apple Business Manager will automatically enroll in your MDM and simplify initial device setup.

That means you can assign names, users, groups and apps before devices are shipped to your location. Even better, especially with the right onboarding workflow provided by a comprehensive MDM: delivered directly to the end user’s home. If you want to get the most out of your Apple fleet, you really need Apple Business Manager.

>> Watch this webinar for a comprehensive overview of how to get started with Apple Business Manager.

Q: What is the difference between Apple Business Manager and MDM?

In a nutshell, Apple Business Manager is what makes MDM possible. As a vehicle to both buy devices in bulk and enroll them into an MDM, Apple Business Manager is indispensable for Apple admin using an MDM. MDM is the management and upkeep of devices, their connections and their OS and apps.

Q: What is Apple School Manager?

This web-based portal helps IT administrators deploy iPad and Mac in schools. It allows you to set up devices and get apps and books for students and teachers. And, especially when in conjunction with a school-focused MDM like Jamf School that partners with educational apps, it can provide tools to create engaging lessons, collaborate, and power remote learning.

Q: What is an Apple ID? What is a Managed Apple ID?

An Apple ID is an identifier and authenticator. Individuals can use an Apple ID to buy items from the App Store and to continue their settings across your iPhone, iPad, Mac, Apple Watch, Vision Pro and other Apple devices with one login. While you can use individual Apple IDs to manage devices in an organization, it’s a more secure and easily controlled process to use Managed Apple IDs instead.

Managed Apple IDs, created by Apple Business Manager, are IDs unique to your organization and separate from the Apple IDs employees create themselves. IT can use Managed Apple IDs to control access and push all apps and tools out to Apple devices. This increases security as each app can be properly vetted before reaching devices.

>> Learn how Managed Apple IDs can help your organization.

Q: How do Apple MDM and iOS MDM work?

Apple MDM manages iOS devices and apps in the same way as it does on Macs or other Apple devices and provides:

  • Device management
  • Patch management
  • App management
  • Security management
  • Compliance enforcement

Q: What is a zero-touch deployment?

Zero-touch deployment is a way for businesses to equip, secure and maintain their Apple devices without ever having to touch the device. This is an absolute must for those with a remote workforce and those who want to push out updates and patches the instant they are available.

>> To learn more, read our beginner’s guide to zero-touch deployment.

Already sold and you just need details? This blog post on how to enable zero-touch deployment for your organization is a detailed, step-by-step instructional blog on how to use Jamf Pro and Jamf Connect to do exactly that.

Q: What is Apple Configurator 2?

Apple Configurator 2 simplifies Apple configuration settings for iPad, iPhone, and Apple TV devices in your school or business.

From one interface screen, IT can view the operating system version, serial number, hardware IDs and addresses, available capacity and log messages of all connected devices. From there, staff can update software, install apps and configuration profiles and more. It isn't an MDM, and is missing key features provided by MDM.

>> Learn how to enroll mobile devices into Jamf Pro using Apple Configurator 2 and an enrollment URL.

Q: What is Apple Push Notification service (APNs)?

APNs enables data propagation on Apple devices without requiring a constant connection.

As a critical layer for Apple deployment programs, security features and MDM, APNs is absolutely vital for organizations focused on security and efficiency. Learn more details in our blog post about APNs.

Q: Is DEP the same as ABM?

DEP, or The Device Enrollment Program, helps businesses easily deploy and configure Apple devices. DEP provides a fast, streamlined way to deploy organization-owned iPad and iPhone devices, Mac computers, and Apple TV purchased directly from Apple or participating Apple Authorized Resellers or carriers.

ABM, or Apple Business Manager, is a web-based portal for IT administrators to deploy iPhone, iPad, Apple TV, and Mac all from one place. Working seamlessly with your mobile device management (MDM) solution, Apple Business Manager makes it easy to automate device deployment, purchase apps and distribute content, and create Managed Apple IDs for employees.

Q: Does Apple use BYOD?

With the right MDM and an efficient Bring Your Own Device (BYOD) program, Apple devices are uniquely situated to protect user privacy and enable enterprise management on the same device, keeping their apps and data separated on the back end while functioning seamlessly for the user.

Q: What can an MDM access on a device?

Apple does not relax its privacy policies for businesses that are managing Apple devices, so access to individual devices is limited.

Mainly, MDMs can monitor:

  • Installed apps
  • OS versions
  • Device inventory
  • Security warnings
  • Configuration settings related to the MDM
  • Remote lock and wipe in case of a lost or stolen device
  • Location tracking, but only in lost mode — not continual monitoring of location.

Q: What can’t an MDM access on a device?

MDMs do not have access to control of a user’s iPhone, even if that iPhone was issued by the company. IT cannot use MDM to move around employee files or send messages on their behalf. They can’t access texts, emails, photos or other personal messages or data within apps on a device.

Q: What is the best MDM solution for iOS?

At the risk of tooting our own horn, Jamf has the in-depth knowledge of iOS that others who haven’t been around as long or who focus more on Android and Windows environments cannot touch.

Our close relationship with Apple also means that our MDM and security products are always fully ready the day Apple releases a new iOS, and we have been at the forefront of many iOS innovations, such as employees using their iPhones as passkeys.

Subscribe to the Jamf Blog

Have market trends, Apple updates and Jamf news delivered directly to your inbox.

To learn more about how we collect, use, disclose, transfer, and store your information, please visit our Privacy Policy.