Last week we sat with an operations lead at a services firm to get her MacBook into Microsoft Intune. Her question was the one most owners ask when they start managing Apple devices: do we have to wipe every machine people are already working on? The short answer is no, and the path you take depends on whether a device is new or already in someone's hands.
Two ways a Mac lands in Intune
Apple Business Manager (ABM) is Apple's portal for assigning devices your company buys directly to your organization. When it's wired up to your Microsoft tenant, a brand new Mac enrolls itself the first time the user signs in with company credentials. No one has to hunt for an app or follow a checklist. That's the clean path, and it's the one you want for anything ordered going forward.
The catch is that the automated ABM path assumes the device can be set up fresh. For a Mac someone is already using every day, you usually can't just reset it on a Tuesday morning. That's where direct enrollment comes in. The user installs the Company Portal app, signs in, and follows the prompts to enroll the machine in place, no wipe required.
| Situation | Path | What the user does |
|---|---|---|
| Brand new Mac you just ordered | Apple Business Manager to Intune | Signs in with company credentials, device enrolls automatically |
| Existing Mac already in daily use | Direct Intune enrollment | Installs Company Portal, signs in, follows the enrollment prompts |
What direct enrollment gets you (and what it doesn't yet)
Even the interim direct-enrollment path gives you meaningful control. Once a Mac is enrolled, you can push applications and apply security policies to it. What you don't get right away is the full lifecycle control, including remote wipe, that comes once devices flow through Apple Business Manager. So it's worth being clear with your team that this is a stepping stone: you get security and policy today, and the tidier automated setup follows as machines cycle through.
Wiping a Mac someone is actively working on means downtime and migration risk. Direct enrollment lets you secure the device immediately, then move it to the automated Apple Business Manager path when it's replaced or reset.
A rough edge worth knowing about
During the walkthrough, the Company Portal app installed fine but didn't show up in Applications for close to ten minutes. macOS runs a verification step after install, and the app can lag behind before it appears. If you're rolling this out to a team, that gap causes a lot of "I don't see it" messages. The fix is simple once you expect it: search Finder for Company Portal, or just wait a few minutes.
Because of that, the better approach for a fleet is to package the Company Portal app and deploy it silently ahead of time, so it's already sitting on every Mac before anyone needs it. Then your instructions to the team are just "open Company Portal and sign in" instead of "go download this and wait."
Don't enforce everything on day one
One more decision that came up: whether to immediately require the company-managed Apple ID on every device. We held off. When people are still cutting over and migrating their data, enforcing that policy too early creates lockouts and support tickets. You can enroll everyone first, then turn on enforcement once the team has had time to move. Sequencing the enforcement after the enrollment keeps the rollout calm.
If you're staring at a mixed bag of Macs
Most small teams don't have the luxury of a fresh fleet. You've got some new machines, some three-year-old ones, and a couple of outliers with a person's name attached to every quirk. A workable plan enrolls what you can today, automates the new arrivals through Apple Business Manager, and schedules the older devices to move over as they get replaced. If you're weighing how to bring your Macs under management without disrupting the people using them, we're happy to talk through the sequencing.