Device management · Apple
Apple Device Management: macOS and iOS
Apple management works differently from Windows or Android. Apple controls exactly what a management server may do through its own MDM protocol, and several of the most useful controls depend on how the device was enrolled in the first place.
How Apple MDM actually works
Apple does not allow a management agent to do whatever it likes. Instead, a device checks in with an approved MDM server and accepts configuration profiles and commands through Apple’s own protocol. What the server may ask for is defined by Apple, not by the vendor.
That means capability differences between MDM vendors on Apple platforms are narrower than on Windows — the meaningful differences are in workflow, automation and reporting, not in what the OS permits.
The concepts that decide your capability
- Apple Business Manager (ABM) — the portal that links purchased hardware and app licences to your organisation. Without it, automated enrolment is not available.
- Automated Device Enrolment (ADE, formerly DEP) — devices bought through an authorised channel enrol automatically at first boot and cannot simply be un-enrolled by the user.
- Supervised — a stronger management state, applied through ADE (or a wipe and re-setup). Many restrictions are supervised-only.
- User-approved enrolment — a manually enrolled Mac requires the user to approve management, and some controls remain unavailable.
- Configuration profiles — the mechanism that carries settings: Wi-Fi, VPN, certificates, restrictions, FileVault and update policy.
What you can enforce: macOS vs iOS
- macOS — FileVault disk encryption with key escrow, software update deferral, application and system-extension policy, firewall settings, certificate and Wi-Fi profiles, remote lock and wipe, plus scripts and inventory when an agent is installed.
- iOS / iPadOS — configuration profiles, app distribution through ABM, restrictions (App Store, AirDrop, camera), Wi-Fi and VPN setup, supervised-only controls, remote lock, locate and wipe. There is no general-purpose agent that can run arbitrary scripts as on macOS.
- Both — passcode policy, remote wipe, activation lock management for company-owned devices, and compliance reporting.
What Infronest covers on Apple — honestly
Infronest manages macOS devices alongside Windows, Linux and Android in one tenant-isolated workspace: inventory, policy, patch and software state, remote access and compliance reporting, with every action recorded in an audit trail.
Infronest does not currently manage iPhone or iPad. If iOS and iPadOS fleet management is your primary requirement, an Apple specialist such as Jamf, or Apple-focused capability in Intune, will serve you better than we will — and we would rather say that than sell you a gap.
Frequently asked questions
What is Apple mobile device management?
Apple MDM is the management framework Apple provides for configuring and securing Macs, iPhones and iPads. An approved MDM server sends configuration profiles and commands to enrolled devices, within the boundaries Apple defines.
What is the difference between supervised and unsupervised Apple devices?
Supervised devices — normally enrolled through Automated Device Enrolment — accept a wider set of restrictions and cannot be casually removed from management by the user. Unsupervised devices accept only a limited subset of controls. Several of the most useful restrictions are supervised-only.
Does Infronest manage iPhones and iPads?
No. Infronest currently manages macOS, Windows, Linux and Android. If iOS and iPadOS management is your main requirement, an Apple-specialist platform will fit better, and we will say so rather than imply coverage we do not have.
Manage every device in one workspace
Start a 14-day free trial — no credit card required.