Skip to content
Living guide · Microsoft 365 & Cloud

Macs and iPhones Under Company Control: How to Manage Apple Devices Properly With Intune

Apple devices are often the least managed machines in a small business: bought on a card, set up with a personal Apple ID, and nobody quite sure what is on them. Here is how we bring Macs, iPhones and iPads under the same control as Windows laptops: enrolled in Intune, encrypted, patched, and with every document saved somewhere it is backed up.

Last reviewed 26 September 2026 Published 26 September 2026 11 min read
Book a Discovery Call
This guide is for you if
  • Your team uses Macs or iPhones and IT only really manages the Windows machines.
  • Company Apple devices were set up with personal Apple IDs and you are not sure who controls them.
  • An insurer, Cyber Essentials or a client has asked whether every device is encrypted, patched and managed, including the Macs.

The short answer

Register company Apple devices in Apple Business Manager, which is free, and link it to Microsoft Intune, so every Mac, iPhone and iPad enrols itself the first time it is switched on and cannot be un-managed by the user. From there Intune enforces the passcode, FileVault encryption and settings, only lets compliant devices reach Microsoft 365, and keeps macOS and iOS updated alongside our patching for third-party apps. Desktop and Documents are redirected to OneDrive, or Google Drive for Workspace clients, so nothing important lives only on the device, and that cloud copy is backed up separately.

In this guide
  1. 1. The Apple gap
  2. 2. Apple Business Manager
  3. 3. Enrolling
  4. 4. Securing them
  5. 5. Patching
  6. 6. Files and backup
  7. 7. Joiners and leavers
  8. 8. How we help
  9. 9. FAQs
01

Why Apple devices are usually the gap

In most businesses we audit, the Windows laptops are managed and the Macs are not. The MacBook was bought on a director's card, set up with their personal Apple ID, and has been updated whenever the owner remembered. The iPhones have company email on them and no passcode rule. Nobody could say whether any of them are encrypted, which version of macOS they run, or what would happen to the data if one was left on a train.

That is not an Apple problem. macOS and iOS are secure platforms and Apple provides first-class tools for managing them. It is a setup problem: nobody connected the Apple devices to the management the business already pays for. Microsoft 365 Business Premium includes Intune, which manages Macs, iPhones and iPads as well as Windows. The job is to use it.

02

Step one: Apple Business Manager, so the business owns the device

Apple Business Manager is Apple's free portal for businesses. It does two things that matter:

  • It records that the business owns the device. Macs, iPhones and iPads bought through an Apple Authorised Reseller or Apple Business can be added to your account automatically by serial number. Devices bought elsewhere can be added with Apple Configurator. Once a device is in Apple Business Manager, it belongs to the company, not to whoever set it up.
  • It hands the device to Intune. We link Apple Business Manager to Intune and assign devices to it. The next time a device is switched on, or after it is wiped, it contacts Apple, is told it belongs to your business, and enrols itself in Intune during the setup screens. The user signs in with their Microsoft 365 account, and the device arrives with the right settings, apps and restrictions already applied.

Devices enrolled this way are supervised, which gives Intune more control, and the management profile cannot be removed by the user. A leaver cannot wipe a MacBook and keep it as a personal machine: after a wipe it re-enrols straight back into the business.

One thing to diarise: Intune talks to Apple devices using an Apple push certificate that must be renewed every year with the same Apple Account it was created with. If it lapses, every Apple device stops receiving management. We track it and renew it; if you manage your own, put a reminder in two calendars.

03

Enrolling Macs and iPhones: the three routes

SituationHow it enrolsWhat you get
New company Mac, iPhone or iPadAutomated device enrolment through Apple Business Manager: switch it on, sign in with the Microsoft 365 accountFull management, supervised, cannot be removed by the user, zero-touch for new starters
Existing company Mac not in Apple Business ManagerAdded to Apple Business Manager with Apple Configurator, then wiped and re-enrolled; or, where that is not practical, enrolled through the Company Portal appFull management. Company Portal enrolment can be removed by an administrator user, so we prefer the Apple Business Manager route
Personal iPhone used for workNo device enrolment. Intune app protection on Outlook, Teams, OneDrive and the Office apps; or Apple's account-driven User Enrollment where more is neededCompany data is protected inside the work apps and can be wiped on its own; the business never sees or controls personal photos, messages or apps

On the Mac, Platform Single Sign-on lets people sign in to the Mac with their Microsoft 365 password and then be signed in to Microsoft apps automatically, so there is one password to remember and one to disable when someone leaves.

For personal phones, our Intune and BYOD guide explains app protection in detail and why it is usually the right answer for staff-owned devices.

Not sure which of these applies to your business? Ask an engineer.

Book a Discovery Call
04

What Intune enforces once a device is enrolled

  • Encryption. FileVault is switched on for every Mac and the recovery key is stored in Intune, not on a sticky note. iPhones and iPads are encrypted whenever a passcode is set, so the passcode is required.
  • Passcode and lock. Minimum length, auto-lock after a few minutes, and a wipe after repeated failed attempts on phones.
  • Compliance and conditional access. Intune marks each device compliant or not: encrypted, passcode set, operating system within a supported version, not jailbroken. Conditional access in Microsoft 365 only lets compliant devices open company email and files. A Mac that has fallen behind on updates is prompted to fix itself before it gets back in.
  • Firewall and security settings. The macOS firewall on, Gatekeeper enforced so only signed apps run, and Microsoft Defender for Endpoint on Macs where your licence includes it.
  • Apps. Microsoft 365 apps, the browser, Company Portal and your line-of-business apps pushed to the device. Staff install approved extras from Company Portal without needing admin rights.
  • Standard user accounts. People work as standard users, not administrators, so malware cannot install itself with their permissions. We can grant temporary admin rights when someone genuinely needs them.
  • Lost or stolen. Remote lock, locate where enabled, and remote wipe. Because the device is in Apple Business Manager, Activation Lock cannot be used to hold it hostage.
05

Patching macOS, iOS and the apps on them

Apple devices need patching as much as Windows ones, and third-party apps on a Mac, Chrome, Zoom, Adobe Reader and the rest, are exactly as exposed as they are on a PC.

  • macOS and iOS updates are managed through Intune's update policies for Apple devices. We set a deadline for each update, so it installs at a time that suits the user but cannot be put off indefinitely, and compliance policies block devices that fall too far behind.
  • Third-party apps on the Mac are covered by the same patch management tooling we use for Windows, so a Mac gets Chrome and Zoom security updates on the same schedule as everyone else.
  • Reporting shows every device's operating system version and outstanding updates, Macs and iPhones included, in the same monthly report.

Our patch management guide and patch management policy set out the timescales: critical updates within 14 days, usually 7.

06

Documents in the cloud, not just on the laptop

The most common thing we find on an unmanaged Mac is the business's documents saved to the Desktop and nowhere else. If that Mac is stolen, dies or is dropped in the sea, the files go with it.

On Microsoft 365, we deploy the OneDrive app to every Mac through Intune and turn on folder backup, so each user's Desktop and Documents are moved into OneDrive silently and kept there. Staff carry on saving where they always did; the files are now in OneDrive, available on any device, with version history, and the setting stops them switching it off. Team files live in SharePoint and Teams, synced to the Mac where people need them offline. Microsoft's documentation notes that folder backup needs the standalone OneDrive app rather than the App Store version, which is the one we deploy.

On Google Workspace, we deploy Google Drive for desktop to every Mac and set it up so work is saved into Drive and shared drives rather than to the local disk.

Either way, the cloud copy is backed up separately. OneDrive, SharePoint and Google Drive keep deleted files for a limited time, and a ransomware infection on a Mac syncs straight up to the cloud. Our Microsoft 365 backup and Google Workspace backup keep an independent copy for seven years in the UK, so a laptop can be lost, wiped or encrypted without losing a single file.

07

New starters and leavers

  • Joiners. A new Mac or iPhone is ordered through us, assigned to your Apple Business Manager account and to Intune before it ships, and arrives sealed. The new starter switches it on, signs in with their Microsoft 365 account, and it builds itself: settings, apps, OneDrive, encryption. See our business hardware page.
  • Leavers. The account is disabled, which blocks access immediately through conditional access. Company devices are wiped remotely or on return and re-enrol automatically for the next person. On a personal phone, only the company data inside the work apps is removed. The joiners and leavers guide has the full checklist.
08

How we bring your Apple devices under control

We audit what you have: every Mac, iPhone and iPad, who set it up, which Apple ID it uses, whether it is encrypted, and what is saved only on the device. Then we set up or connect Apple Business Manager and the push certificate, build the Intune policies, move each device across on a plan that does not lose anyone's files, and add the Macs to patching, monitoring and backup alongside everything else.

It is included in managed IT support for clients, and available as a project for businesses that want their Apple estate sorted once.

09

Frequently asked questions

Can Microsoft Intune manage Macs and iPhones?

Yes. Intune, included in Microsoft 365 Business Premium, manages macOS, iOS and iPadOS as well as Windows: enrolment, settings, encryption, apps, updates, compliance and remote wipe. For the best control, company devices are enrolled through Apple Business Manager.

What is Apple Business Manager and does it cost anything?

It is Apple's free portal for businesses. It records that the business owns each device and hands new or wiped devices to Intune automatically, so they enrol themselves and the management cannot be removed by the user.

Our Macs were set up with personal Apple IDs. Can we fix that?

Yes. We back up the user's data to OneDrive or Google Drive, add the Mac to Apple Business Manager with Apple Configurator, wipe it, and let it re-enrol as a company device. The user signs back in with their Microsoft 365 account and their files come back from the cloud.

Do we have to manage staff's personal iPhones?

No. For personal phones we protect company data inside the work apps with Intune app protection, without enrolling the device. The business can remove its own data and never sees personal content.

How are Macs kept up to date?

macOS updates are enforced through Intune update policies with deadlines, and third-party apps such as Chrome and Zoom are patched by the same tooling we use on Windows. Devices that fall behind are blocked from company data until they update.

What happens if a MacBook is stolen?

It is encrypted with FileVault, so the data cannot be read. We lock or wipe it remotely, and because it belongs to your Apple Business Manager account it cannot be reactivated as someone else's device. The documents are in OneDrive or Google Drive and backed up, so nothing is lost.

Get your Macs and iPhones under control

We will audit every Apple device, tell you who controls it, whether it is encrypted and patched, and what data lives only on it, and give you a plan to bring it all under Intune.

  • Every Mac, iPhone and iPad and who set it up.
  • Encryption, update and management status for each.
  • Files saved only on devices, and how to move them.
  • What it takes and costs to bring them under control.
Book an Apple device review

Sources

Prices and product facts on this page were checked against the following Microsoft pages on the dates shown.

  1. 1.Apple: Intro to Apple Business Manager · accessed 26 September 2026
  2. 2.Microsoft Learn: Set up automated device enrolment for macOS · accessed 26 September 2026
  3. 3.Microsoft Learn: Set up automated device enrolment for iOS and iPadOS · accessed 26 September 2026
  4. 4.Microsoft Learn: Apple User Enrollment in Intune · accessed 26 September 2026
  5. 5.Microsoft Learn: Encrypt macOS devices with FileVault using Intune · accessed 26 September 2026
  6. 6.Microsoft Learn: Configure update policies for Apple devices · accessed 26 September 2026
  7. 7.Microsoft Entra: macOS Platform Single Sign-on overview · accessed 26 September 2026
  8. 8.Microsoft Learn: Deploy and configure the OneDrive sync app for Mac · accessed 26 September 2026
  9. 9.Google Workspace Admin Help: Set up Drive for desktop · accessed 26 September 2026

What has changed on this page

  • 26 September 2026Page published.

More guides

Related reading