Confirm the employee is in the system of record
HR or the hiring manager should have the employee's full legal name, start date, work
email, and role assigned before purchasing places the device order. Most mismatches
downstream trace back to this step.
Pick the device role
Decide whether the device is an employee Mac, a shared iPad, a kiosk iPhone, or a
field-use device. The role determines which MDM Blueprint or configuration profile
applies, which apps are assigned, and which restrictions are enforced.
Buy through a linked channel
Devices should be purchased through Apple directly or a linked Apple Authorized
Reseller so they auto-enroll into Apple Business. Consumer retail purchases or
unofficial channels land outside Apple Business and need manual enrollment later.
Pre-create the Managed Apple Account
Create the employee's Managed Apple Account on the business domain in advance, issue
credentials through the same channel the company uses for other SaaS access, and verify
the account before shipment.