Apple Business β Enrollment Setup Guide (Working Draft)
Setting up Apps, Configurations, Blueprints, and User Groups before device enrollment
Scope of this document: This guide covers everything you set up in Apple Business to prepare for device enrollment β acquiring apps, building configurations, assembling Blueprints, and creating user groups. Actually getting a device into BYOD enrollment is a separate document (to be written next).
Status: working draft from a live walkthrough on 2026-06-29. Facts to be verified are flagged inline.
The big idea: build in the reverse of the menu order
The top menu reads People β Devices β Apps & Services, but that's effectively backwards from how an admin actually builds things. The biggest job an admin has is managing app access and configuration, so apps and configurations must exist before you can bundle them into a Blueprint, and Blueprints should exist before you create the groups and users that receive them.
Recommended build sequence (the order this guide follows):
- Apps & Services β acquire the apps you need (via View Store).
- Devices β Configurations β set up your configurations (e.g., iCloud).
- Devices β Blueprints β build Blueprints that bundle the apps + configurations.
- People β User Groups β create your user groups (e.g., a Staff Smart Group).
- People β Users β create/onboard users, who then flow into groups β Blueprints automatically.
Why groups instead of per-user assignment: Blueprints have users assigned to them (rather than Blueprints being assigned to each user). Because the relationship runs that direction, organizing people into User Groups up front is far cleaner than wiring up each user individually.
1. Acquire apps in the Store (Apps & Services)
Apps are licensed and assigned to a specific MDM. In this environment, previously acquired apps were all assigned to JAMF, so any app you want available through Apple Business has to be assigned to Apple Business specifically.
For each app you want under Apple Business:
- Open Apps & Services β View Store and find the app.
- Use Assign to and select Apple Business.
- Enter a quantity of licenses.
- Click Get.
The app's page then shows Manage Licenses, with running counts of In Use and Available licenses.
Note: The same app can hold separate license pools across MDMs (e.g., some licenses on JAMF, some on Apple Business). Assigning to Apple Business does not disturb the JAMF assignment.
π Apple reference: Distribute content with Apps and Books
2. Set up Configurations (Devices)
Configurations are the reusable settings you'll attach to a Blueprint. The iCloud configuration is a good example (see the iCloud use case below).
When you save a configuration that isn't attached to anything, Apple Business will prompt that it has no Blueprint assigned β that's expected; you attach it in the next step.
π Apple reference: Manage the built-in device management service in Apple Business
iCloud configuration β the use case
The managed iCloud configuration gives an employee a business iCloud Drive that is fully separated from their personal one:
Side-by-side isolation in the Files app. In the native iOS Files app, under Browse β Locations, the employee sees two distinct storage locations:
- iCloud Drive β personal storage, tied to their personal Apple Account.
- iCloud Drive β [Organization Name] β the business storage, tied to their Managed Apple Account, clearly marked as belonging to the organization.
The user can manually move or save files into the business folder exactly like any other cloud provider (OneDrive, Google Drive).
Automatic routing via Managed apps. Apple's Managed Open In framework keeps the two worlds from crossing:
- Managed apps (pushed via MDM) are designated "Managed." When they save or sync to iCloud, iOS automatically routes that data to the business iCloud Drive / corporate volume.
- Personal (unmanaged) apps do not automatically write into the business iCloud Drive β iOS won't silently route their data there.
Important distinction β automatic routing vs. manual file moves. The wall above is about apps exchanging data automatically; Managed Open In is a configurable policy that defines what data can pass between managed and unmanaged apps and accounts. It does not necessarily stop a person from manually moving a file. In the Files app a user can drag or "Move to Folder" a personal file into the business iCloud Drive, just like any other cloud provider β and once a file lives in the business Drive, it falls under organizational control. Whether manual cross-over is allowed depends on the Managed Open In / data-separation settings configured for this org.
Confirmed: a user can manually move or copy files from the personal (Private) iCloud Drive into the business iCloud Drive using the Files app. Once a file lands in the business Drive, it lives in business storage and falls under organizational control (sharing, backup, and potential revocation on offboarding).
Target use case: a worker with a personal iPhone and laptop plus a company-owned desktop can share the same work iCloud data and Drive across all of those devices.
Storage (confirmed): the standard business iCloud storage for a Managed Apple Account is 5 GB. (Apple Business plans can offer more β customizable up to 2 TB per employee β but the standard allocation here is 5 GB.) Keep that ceiling in mind when deciding how much data should live in the business Drive.
π Apple references: iCloud for Managed Apple Accounts Β· About Managed Apple Accounts in Apple Business Manager Β· Manage organizational data on Apple devices (Managed Open In)
Transitioning an existing personal app (and its data) to business
If a user already has an app personally that the business also uses β and that app's data should be business data (so it can be shared, backed up, and managed at the org level) β consider transitioning the app and its data from personal to business. The process:
- Copy the data from the personal (Private) iCloud Drive into the business iCloud Drive.
- Delete the personal copy of the app from the device.
- Reinstall the app from Apple Business (so it's now a managed app).
Once reinstalled as managed, the app's new data automatically routes to the business iCloud Drive.
β οΈ Watch the 5 GB ceiling when copying existing data into the business Drive, and remember that managed apps and their data can be revoked/wiped by the org on offboarding β which is exactly why you only want true business data over there.
To be determined later β standard dual-use apps (e.g., Numbers, Pages)
Apps like Numbers are different: they're standard, pre-installed, and used for both personal and business work. Two approaches, and it's a real trade-off:
- Option A β Make it managed (full transition). Reinstall Numbers from Apple Business so it's managed. But a managed app routes all its iCloud data to the business Drive β so personal spreadsheets would also land in business storage and under org control. Usually not what you want for a dual-use app.
- Option B β Leave the app personal, file business docs manually. Keep Numbers as a personal app, and move only the business files into the business iCloud Drive. New files default to personal iCloud and have to be moved over, but once moved they're reachable via Open Recent or by browsing the business iCloud Drive.
My recommendation: let the nature of the app decide.
- Single-purpose / org-specific apps (e.g., Planning Center) β fully transition to managed. All their data is business data anyway, so managed routing is exactly right.
- General-purpose, dual-use apps (Numbers, Pages, etc.) β keep them personal (Option B) and manually file business documents into the business Drive. Making them managed would sweep personal files into org-controlled storage and expose them to revocation/wipe on offboarding β a bigger downside than the minor friction of moving the occasional business file.
The one thing to decide per user is how much dual-use work they do: a user who lives in Numbers for business all day might justify Option A (accepting that personal files go to business too), while most users are better served by Option B.
TBD to validate on a device: with a personal Numbers app, confirm the exact "save then move to business Drive" flow and whether moved files reliably show under Open Recent afterward.
3. Build the Blueprint (Devices β Blueprints)
A Blueprint bundles apps + configurations and is the thing your user groups are assigned to. This walkthrough uses a Blueprint named Staff BYOD.
3a. Add the configuration to the Blueprint
After saving the Staff iCloud configuration, the prompt noted it had no Blueprint. Add it to the Staff BYOD Blueprint so the iCloud setup applies to everyone in the Staff group.
3b. Add apps to the Blueprint
- Confirm the apps you acquired now appear under Devices β Built-in Management β Managed Apps.
- Open Staff BYOD β Apps and click Edit.
- Select or deselect the apps that should apply to this Blueprint.
π Apple reference: Apply Blueprints in Apple Business
4. Create User Groups (People β User Groups)
Users themselves are created and managed under the main-menu People tab. Within People you build User Groups, and there are two kinds:
- Regular group β you manually add each user to the group.
- Smart Group β you pick a Role, and any user with that role is added automatically.
For the standard staff role, a Smart Group named "Staff" was created so new staff are picked up automatically with no manual maintenance.
How conflicts resolve when a user is in multiple groups
A user can belong to a Smart Group and one or more Regular Groups at the same time, and they receive what each group's Blueprint assigns β membership is cumulative, not either/or. There is no automatic "most restrictive" or "most liberal" rule. Resolution works in three layers:
- Apps are additive (union). The user gets the combined set of apps from all their Blueprints; duplicates simply aren't installed twice.
- Non-conflicting configurations stack. Settings that don't collide are both applied. Apple's own example: one Blueprint's Wi-Fi network and another's different Wi-Fi network β the device simply sees both networks.
- Genuine conflicts use admin-defined priority. When two Blueprints set the same configuration to different values, Apple Business won't silently choose the stricter or looser one β it requires you to assign a priority order before it lets you save. The higher-priority Blueprint's value wins.
Don't confuse configurations with privileges. The priority mechanic above governs device configurations/restrictions delivered by Blueprints. A user's administrative privileges in Apple Business (Administrator, Manager, Staff, etc.) come from their Role, not from group membership, and are not resolved by Blueprint priority.
So a user in the Smart Staff group who is also manually added to a Regular group with extra restrictions gets the combined apps and configurations, with any direct setting conflict decided by whichever Blueprint you ranked higher.
π Apple references: Apply Blueprints in Apple Business Β· Intro to users and user groups
5. Point the Blueprint at the group (and let the Smart Group take over)
Back in Devices, assign the Staff BYOD Blueprint to the Staff user group instead of to individual users. Because the Staff Smart Group auto-populates by role, every new staff member inherits the Blueprint automatically.
Tip: If a Blueprint still has an individual user directly assigned, remove them so the Smart Group's user list takes precedence. This avoids conflicting/duplicate assignment and keeps the group as the single source of truth.
6. Verify on an enrolled device
On an iPhone enrolled in Staff BYOD, open the Apple Business app. Apps appear in one of three states:
| State | Meaning |
|---|---|
| Installed | App was already on the device (installed personally by the user). |
| Open | App was deployed via Apple Business and is already installed (ready to launch). |
| Install | Newly added Blueprint app, not yet on the device β tap to deploy. |
Tapping Install on the new apps deploys them to the device.

Above: the Apple Business app Apps tab. "Bible" shows Open; Calvary Chapel Vero Beach, Planning Center, and Planning Center Check-Ins show Installed; Planning Center Services and Square Point of Sale (POS) are the newly added Blueprint apps mid-install.
Two things worth knowing:
- The managed apps aren't locked inside the Apple Business app β they also appear on the iPhone Home Screen for normal, one-tap access. No extra hoops to open them.
- The business iCloud Drive shows up in Files β Browse, clearly labeled as belonging to the organization (separate from personal iCloud Drive).
Where this guide ends
At this point the setup for enrollment is complete: apps acquired and assigned, configurations built, the Staff BYOD Blueprint assembled and pointed at the Staff Smart Group, and the result verified on a live device.
Next document: Getting a device into BYOD enrollment β the actual device-side enrollment process β will be covered separately.
π Apple reference for the next doc: Enrollment methods for built-in device management
Open items to resolve before publishing
- [x] ~~Confirm managed iCloud storage amount~~ β confirmed: 5 GB standard.
- [x] ~~Confirm files can be moved Private β Business~~ β confirmed: yes, via Files app; moved files come under org control.
- [ ] Validate the dual-use app flow on a device (Numbers: save β move to business Drive β confirm it appears under Open Recent).
- [x] ~~Confirm exact menu labels/paths~~ β confirmed correct.
- [x] ~~Decide on the JAMF-vs-Apple-Business licensing note~~ β keeping it in the guide.