← ABM Guides  Β·  Download PDF ↓

Apple Business β€” Enrollment Setup Guide (Working Draft)

Setting up Apps, Configurations, Blueprints, and User Groups before device enrollment

Scope of this document: This guide covers everything you set up in Apple Business to prepare for device enrollment β€” acquiring apps, building configurations, assembling Blueprints, and creating user groups. Actually getting a device into BYOD enrollment is a separate document (to be written next).

Status: working draft from a live walkthrough on 2026-06-29. Facts to be verified are flagged inline.


The big idea: build in the reverse of the menu order

The top menu reads People β†’ Devices β†’ Apps & Services, but that's effectively backwards from how an admin actually builds things. The biggest job an admin has is managing app access and configuration, so apps and configurations must exist before you can bundle them into a Blueprint, and Blueprints should exist before you create the groups and users that receive them.

Recommended build sequence (the order this guide follows):

  1. Apps & Services β€” acquire the apps you need (via View Store).
  2. Devices β†’ Configurations β€” set up your configurations (e.g., iCloud).
  3. Devices β†’ Blueprints β€” build Blueprints that bundle the apps + configurations.
  4. People β†’ User Groups β€” create your user groups (e.g., a Staff Smart Group).
  5. People β†’ Users β€” create/onboard users, who then flow into groups β†’ Blueprints automatically.

Why groups instead of per-user assignment: Blueprints have users assigned to them (rather than Blueprints being assigned to each user). Because the relationship runs that direction, organizing people into User Groups up front is far cleaner than wiring up each user individually.


1. Acquire apps in the Store (Apps & Services)

Apps are licensed and assigned to a specific MDM. In this environment, previously acquired apps were all assigned to JAMF, so any app you want available through Apple Business has to be assigned to Apple Business specifically.

For each app you want under Apple Business:

  1. Open Apps & Services β†’ View Store and find the app.
  2. Use Assign to and select Apple Business.
  3. Enter a quantity of licenses.
  4. Click Get.

The app's page then shows Manage Licenses, with running counts of In Use and Available licenses.

Note: The same app can hold separate license pools across MDMs (e.g., some licenses on JAMF, some on Apple Business). Assigning to Apple Business does not disturb the JAMF assignment.

πŸ“Ž Apple reference: Distribute content with Apps and Books


2. Set up Configurations (Devices)

Configurations are the reusable settings you'll attach to a Blueprint. The iCloud configuration is a good example (see the iCloud use case below).

When you save a configuration that isn't attached to anything, Apple Business will prompt that it has no Blueprint assigned β€” that's expected; you attach it in the next step.

πŸ“Ž Apple reference: Manage the built-in device management service in Apple Business

iCloud configuration β€” the use case

The managed iCloud configuration gives an employee a business iCloud Drive that is fully separated from their personal one:

Side-by-side isolation in the Files app. In the native iOS Files app, under Browse β†’ Locations, the employee sees two distinct storage locations:

The user can manually move or save files into the business folder exactly like any other cloud provider (OneDrive, Google Drive).

Automatic routing via Managed apps. Apple's Managed Open In framework keeps the two worlds from crossing:

Important distinction β€” automatic routing vs. manual file moves. The wall above is about apps exchanging data automatically; Managed Open In is a configurable policy that defines what data can pass between managed and unmanaged apps and accounts. It does not necessarily stop a person from manually moving a file. In the Files app a user can drag or "Move to Folder" a personal file into the business iCloud Drive, just like any other cloud provider β€” and once a file lives in the business Drive, it falls under organizational control. Whether manual cross-over is allowed depends on the Managed Open In / data-separation settings configured for this org.

Confirmed: a user can manually move or copy files from the personal (Private) iCloud Drive into the business iCloud Drive using the Files app. Once a file lands in the business Drive, it lives in business storage and falls under organizational control (sharing, backup, and potential revocation on offboarding).

Target use case: a worker with a personal iPhone and laptop plus a company-owned desktop can share the same work iCloud data and Drive across all of those devices.

Storage (confirmed): the standard business iCloud storage for a Managed Apple Account is 5 GB. (Apple Business plans can offer more β€” customizable up to 2 TB per employee β€” but the standard allocation here is 5 GB.) Keep that ceiling in mind when deciding how much data should live in the business Drive.

πŸ“Ž Apple references: iCloud for Managed Apple Accounts Β· About Managed Apple Accounts in Apple Business Manager Β· Manage organizational data on Apple devices (Managed Open In)

Transitioning an existing personal app (and its data) to business

If a user already has an app personally that the business also uses β€” and that app's data should be business data (so it can be shared, backed up, and managed at the org level) β€” consider transitioning the app and its data from personal to business. The process:

  1. Copy the data from the personal (Private) iCloud Drive into the business iCloud Drive.
  2. Delete the personal copy of the app from the device.
  3. Reinstall the app from Apple Business (so it's now a managed app).

Once reinstalled as managed, the app's new data automatically routes to the business iCloud Drive.

⚠️ Watch the 5 GB ceiling when copying existing data into the business Drive, and remember that managed apps and their data can be revoked/wiped by the org on offboarding β€” which is exactly why you only want true business data over there.

To be determined later β€” standard dual-use apps (e.g., Numbers, Pages)

Apps like Numbers are different: they're standard, pre-installed, and used for both personal and business work. Two approaches, and it's a real trade-off:

My recommendation: let the nature of the app decide.

The one thing to decide per user is how much dual-use work they do: a user who lives in Numbers for business all day might justify Option A (accepting that personal files go to business too), while most users are better served by Option B.

TBD to validate on a device: with a personal Numbers app, confirm the exact "save then move to business Drive" flow and whether moved files reliably show under Open Recent afterward.


3. Build the Blueprint (Devices β†’ Blueprints)

A Blueprint bundles apps + configurations and is the thing your user groups are assigned to. This walkthrough uses a Blueprint named Staff BYOD.

3a. Add the configuration to the Blueprint

After saving the Staff iCloud configuration, the prompt noted it had no Blueprint. Add it to the Staff BYOD Blueprint so the iCloud setup applies to everyone in the Staff group.

3b. Add apps to the Blueprint

  1. Confirm the apps you acquired now appear under Devices β†’ Built-in Management β†’ Managed Apps.
  2. Open Staff BYOD β†’ Apps and click Edit.
  3. Select or deselect the apps that should apply to this Blueprint.

πŸ“Ž Apple reference: Apply Blueprints in Apple Business


4. Create User Groups (People β†’ User Groups)

Users themselves are created and managed under the main-menu People tab. Within People you build User Groups, and there are two kinds:

For the standard staff role, a Smart Group named "Staff" was created so new staff are picked up automatically with no manual maintenance.

How conflicts resolve when a user is in multiple groups

A user can belong to a Smart Group and one or more Regular Groups at the same time, and they receive what each group's Blueprint assigns β€” membership is cumulative, not either/or. There is no automatic "most restrictive" or "most liberal" rule. Resolution works in three layers:

  1. Apps are additive (union). The user gets the combined set of apps from all their Blueprints; duplicates simply aren't installed twice.
  2. Non-conflicting configurations stack. Settings that don't collide are both applied. Apple's own example: one Blueprint's Wi-Fi network and another's different Wi-Fi network β†’ the device simply sees both networks.
  3. Genuine conflicts use admin-defined priority. When two Blueprints set the same configuration to different values, Apple Business won't silently choose the stricter or looser one β€” it requires you to assign a priority order before it lets you save. The higher-priority Blueprint's value wins.

Don't confuse configurations with privileges. The priority mechanic above governs device configurations/restrictions delivered by Blueprints. A user's administrative privileges in Apple Business (Administrator, Manager, Staff, etc.) come from their Role, not from group membership, and are not resolved by Blueprint priority.

So a user in the Smart Staff group who is also manually added to a Regular group with extra restrictions gets the combined apps and configurations, with any direct setting conflict decided by whichever Blueprint you ranked higher.

πŸ“Ž Apple references: Apply Blueprints in Apple Business Β· Intro to users and user groups


5. Point the Blueprint at the group (and let the Smart Group take over)

Back in Devices, assign the Staff BYOD Blueprint to the Staff user group instead of to individual users. Because the Staff Smart Group auto-populates by role, every new staff member inherits the Blueprint automatically.

Tip: If a Blueprint still has an individual user directly assigned, remove them so the Smart Group's user list takes precedence. This avoids conflicting/duplicate assignment and keeps the group as the single source of truth.


6. Verify on an enrolled device

On an iPhone enrolled in Staff BYOD, open the Apple Business app. Apps appear in one of three states:

State Meaning
Installed App was already on the device (installed personally by the user).
Open App was deployed via Apple Business and is already installed (ready to launch).
Install Newly added Blueprint app, not yet on the device β€” tap to deploy.

Tapping Install on the new apps deploys them to the device.

Apple Business app on iPhone showing the three app states

Above: the Apple Business app Apps tab. "Bible" shows Open; Calvary Chapel Vero Beach, Planning Center, and Planning Center Check-Ins show Installed; Planning Center Services and Square Point of Sale (POS) are the newly added Blueprint apps mid-install.

Two things worth knowing:


Where this guide ends

At this point the setup for enrollment is complete: apps acquired and assigned, configurations built, the Staff BYOD Blueprint assembled and pointed at the Staff Smart Group, and the result verified on a live device.

Next document: Getting a device into BYOD enrollment β€” the actual device-side enrollment process β€” will be covered separately.

πŸ“Ž Apple reference for the next doc: Enrollment methods for built-in device management


Open items to resolve before publishing

Apple documentation index

Apple Business Manager admin guide Β· CoderTricks Β· referenced from Apple’s official documentation