Step 1 — Prep Apple Business
Confirm the Mac isn’t already in another org. In Apple Business
Preferences → Device Management Services → Management
Assignment → Default Assignment, set the target MDM server as default
for Apple Configurator additions.
Step 2 — Prep the Mac
Sign out of Find My. Disable Activation Lock. Take a backup. Note the local
admin password and confirm it unlocks FileVault if FileVault is on.
Step 3 — Boot to macOS Recovery
Apple silicon: shut down, press and hold the power button until “Loading
startup options” appears, choose Options. T2 Intel:
hold Command-R at boot.
Step 4 — Open Terminal
From the Recovery menu bar: Utilities → Terminal. Verify network
connectivity — open a second Terminal tab and ping apple.com
if in doubt.
Step 5 — Run the script
Run sh <(curl -s add2abm.inetum.zone). The script prompts
interactively before making changes. It clears the
.AppleSetupDone flag and temporarily relocates local user records
so macOS replays Setup Assistant on next boot.
Step 6 — Reboot into Setup Assistant
The Mac behaves like a freshly activated device: language picker, Wi-Fi join,
and so on. Join a network that can reach Apple’s activation servers.
Step 7 — Pair with Apple Configurator
On the iPhone, open Apple Configurator, sign in with a Managed Apple Account,
tap Add to Apple Business Manager. Scan the particle image on
the Mac, or tap Pair Manually and enter the six-digit code.
Step 8 — Mac claims into Apple Business
A screen reading approximately “This Mac has been assigned to
[Organization]” appears. The device now shows up in Apple Business as an
Apple Configurator-added Mac, ready for MDM assignment.
Step 9 — Complete MDM ADE enrollment
If auto-advance is set, Setup Assistant proceeds into the MDM’s ADE flow
and the management profile installs. Otherwise finish Setup Assistant and let
the MDM push the profile on first check-in.
Step 10 — Log back in and verify
The original local user account still appears at the login window. Sign in
with the existing password; documents, apps, Photos library, and iCloud
sign-in state should all be intact. add2abm restores the relocated user
records automatically.