Back

Enrolment methods

There are five ways to enrol a device, and the right one depends on your existing setup, your platform mix, and whether you want IT or the employee to drive it. This article compares all five so you can pick without trial and error.

Overview

Start here before your first rollout. Employee enrolment always works on every supported platform, so it is your safe default and your fallback. Everything else is faster or more controlled, but has a prerequisite.

Method

Use it when

Platforms

Driven by

Zero touch

The goal to move towards, device by device

macOS, Windows, iOS/iPadOS. Not Android yet

IT

Employee enrolment

Default. Always works

All platforms

Employee

Account-driven enrolment

You federate accounts in Apple Business

iOS/iPadOS. macOS coming

Employee

Silent agent deployment

You already deploy packages (migration)

macOS, Windows, Linux

IT

Migrating with Apple Business

Macs already in Apple Business on macOS 26+

macOS, iOS/iPadOS

IT


 

What each one costs you

  • Zero touch gives the most control: the device cannot be activated without authenticating, which protects you against theft, and management survives a wipe. The price is initial setup in Apple Business or Autopilot, and it does not work on devices that were never registered there.
     
  • Employee enrolment needs no infrastructure at all and covers every platform. The price is that it depends on someone doing it, and the employee needs administrator rights on their own machine.
     
  • Account-driven enrolment keeps work and personal data cryptographically separate, which makes it the easiest conversation for a personal phone. The price is federating your identity provider with Apple Business.
     
  • Silent agent deployment needs no employee interaction — useful when migrating a fleet. One catch on macOS: the agent installs silently but the employee still has to accept the MDM profile.
     
  • Migrating with Apple Business reassigns Macs already in Apple Business without wiping them, which is the only method that works on machines already out in the field. It needs macOS 26 or later.

 

How to use — pick by platform

  1. macOS. Zero touch for new devices bought through an authorised reseller. Apple Business migration for machines already in Apple Business on macOS 26+. Silent deployment if you already have a package tool. Employee enrolment as the fallback.
  2. Windows. Zero touch through Autopilot for new devices. Silent deployment for migrations. Employee enrolment as the fallback.
  3. Linux. Silent deployment if you have a package tool, otherwise employee enrolment.
  4. iOS and iPadOS. Zero touch for devices bought through a reseller and assigned in Apple Business. Apple Business migration for devices already there. Account-driven enrolment for personal devices where privacy matters. Employee enrolment as the fallback.
  5. Android. Employee enrolment is the only option — employees enrol their own devices.

 

Tips and Best Practices

  • Do not try to start with zero touch everywhere. It is where you want to end up, not where you start. Roll out with employee enrolment, then move each new hardware order onto zero touch.
  • Check Apple Business membership before you promise a migration date. Whether a Mac is registered there decides which of two completely different procedures you follow.
  • On Android, plan for employee enrolment only. The other methods are unavailable, so your Android rollout is always a communication exercise rather than a technical one.
  • Use silent deployment for the migration and zero touch for new devices. They are complements, not alternatives.
 

 

Troubleshooting and FAQ

Troubleshooting

  • A device cannot use zero touch. It was never registered in Apple Business or Autopilot. Registration happens at purchase, so a device bought outside those channels cannot be added retroactively — use employee enrolment or silent deployment instead.
     
  • Silent deployment finished on a Mac but the device is not managed. Expected. On macOS the agent installs silently, but the MDM profile still needs the employee to accept it. For a genuinely touchless result you need zero touch.
     
  • Account-driven enrolment does not appear as an option. Your identity provider is not federated with Apple Business. Without federation the employee cannot authenticate, so the method is unavailable.

FAQ

  1. Which method should we default to?
    Employee enrolment. It works on every platform and needs no prior setup, which makes it the right starting point and the right fallback.
     
  2. Can we mix methods?
    Yes, and most organisations do — zero touch for new hardware, silent deployment for the existing fleet, employee enrolment for anything that falls outside both.
     
  3. Does migrating wipe the device?
    No. Apple Business migration and silent deployment both keep the employee's data, apps and session.

Was this article helpful?

Give feedback about this article

Can’t find what you’re looking for?

Our customer care team is here for you.

Contact us

Knowledge Base Software powered by Helpjuice