Moving unmanaged Apple devices into MDM: a migration guide
Years of hand-configured Macs, iPhones and personal Apple IDs can be brought under proper management without mass disruption. Here is the migration path that works.

Most Apple estates in Indian businesses were never designed; they accumulated. A founder's MacBook, then the design team's, then iPhones for sales, each set up by hand with whatever Apple ID was nearest. Bringing that estate under management is entirely achievable without wiping everyone's device on the same weekend, but it does need to be run as a migration with phases, not as a tool purchase. This is the sequence that works, and the traps that make such projects fail.
Phase zero: inventory and honesty
You cannot migrate what you have not counted. Build a list of every Apple device doing company work: owner, model, company-owned or personal, which Apple ID it uses, and whether Find My is enabled (this last one matters enormously later, because it means Activation Lock is tied to that personal account). Expect surprises: devices bought on personal cards and expensed, leavers' old laptops in drawers, a Mac mini under someone's desk running something important. Write the inventory down properly; it becomes the migration tracker for everything that follows. The inventory is also where you separate the estate into company-owned devices, which will be fully managed, and personal devices, which will get user enrolment instead. Mixing those two paths is the single most common planning error.
Phase one: foundations before any enrolment
Register for Apple Business Manager, stand up the MDM (Jamf or Intune, a decision worth making deliberately), connect the two, and link your reseller so future purchases enrol automatically. Doing foundations first means every device you touch from here on is touched once. Businesses that start enrolling into a half-configured MDM end up doing the work twice, and their users remember the second time.
Phase two: stop the bleeding
Before migrating old devices, fix the pipeline: from this point, every new device is zero-touch enrolled from the box. This costs almost nothing once ABM is linked and immediately caps the size of the problem. Fleets refresh faster than people expect; a meaningful fraction of your migration completes itself through ordinary replacement if new purchases are done right.
Phase three: enrol existing devices, gently
Existing Macs can enrol into management over the air without erasure: users run an enrolment link, approve the profile, and management begins. You do not get the full supervision that box-fresh enrolment provides, but you get the controls that matter most (encryption enforcement, patching, inventory, remote lock) with minutes of user disruption. Full ABM-owned enrolment can then arrive naturally per device at its next erase: repair, handover or refresh. For iPhones and iPads the same logic applies, with supervision arriving when the device is reset.
Run this in waves: a pilot group of friendly users first, then team by team, with the enrolment window announced and short. Momentum matters; migrations that run open-ended never close.
Phase four: untangle the Apple IDs
The hardest part is not technical. Years of personal Apple IDs mean company devices Activation-Locked to personal accounts, app purchases stranded on individuals, and iCloud backups mixing personal and company data. The pattern that works: introduce Managed Apple Accounts, federated to your identity provider; move app licensing to Apps and Books so apps stop depending on anyone's personal account; and clear personal Activation Lock from company devices one by one with the owner present, which takes a minute each when the person is cooperative and is genuinely painful when they have already left. That asymmetry is the argument for doing this phase promptly rather than someday.
What not to do
- Do not announce a mass mandatory wipe. It is unnecessary for most of the value and it turns the whole workforce against the project on day one.
- Do not fully manage personal devices. Use user enrolment for BYOD; the separation protects both sides.
- Do not push a heavy restriction set on day one. Enrol first with a light touch, then tighten deliberately, with notice.
- Do not skip the leavers. Devices assigned to people no longer employed are your highest-risk items and your least defended.
What done looks like
Every company device enrolled and reporting; every new device zero-touch; encryption and updates enforced and evidenced; company devices free of personal Activation Lock; BYOD on user enrolment behind conditional access; and one asset list that matches reality. For a fleet under a hundred devices this is typically a six-to-ten-week programme run alongside normal work, with the Apple ID untangling as the long tail. It is the exact programme our Apple device management service runs for Indian businesses, pilot wave included.
Effort by fleet size, honestly
For a team planning the work, rough shapes help more than promises. Under thirty devices: foundations in week one, enrolment in weeks two and three, Apple ID cleanup inside a month, largely one person's part-time project. Thirty to a hundred: the six-to-ten-week programme described above, with a real pilot wave and communication plan. Beyond a hundred, or spread across cities: the same phases stretched by logistics rather than by technology, since over-the-air enrolment does not care where a Mac sits, but coordination, spares and the long tail of exceptions do. In every size band, the calendar is dominated by the human steps, waiting for D-U-N-S verification, scheduling users, chasing leavers about Activation Lock, and almost never by the tooling.
One planning decision deserves emphasis: appoint a single owner for the migration with the authority to close exceptions. Estates where "IT generally" owns the project develop a permanent residue of special-case devices; estates with a named owner and a weekly exception review reach one hundred percent, because someone is paid to be annoyed by the gap.
Communicate twice at each wave: once before, saying what will happen and what users must do (usually nothing beyond clicking approve), and once after, saying what changed and where to raise problems. Migrations feel imposed exactly in proportion to how little was said in advance.
Frequently asked questions
Will users lose data during enrolment?
Over-the-air enrolment of an existing device installs a management profile; it does not erase anything. Data loss risk concentrates in the later, optional step of erase-and-re-enrol for full supervision, which is why that step is best scheduled at natural reset moments with backups verified first.
Can employees refuse enrolment on company-owned devices?
A company device is company infrastructure, and managing it is as normal as managing the file server. Clear communication about what management does and does not see defuses most resistance; conditional access, where company resources require an enrolled device, settles the remainder without confrontation.
What about the Mac that cannot be touched because it runs something critical?
Every estate has one. Enrol it over the air (no disruption), exempt it from restart-forcing policies temporarily, and plan its replacement properly instead of leaving it as permanent shadow infrastructure. Management makes such machines visible, which is the first step to retiring them safely.
How do we handle devices locked to a leaver's personal Apple ID?
Contact the person and ask them to remove the device from their account, which they can do remotely. Failing that, Apple has processes for organisations to request unlocks with proof of purchase, which is slower and depends on your paperwork. The durable fix is preventing recurrence: ABM ownership and managed Activation Lock on every company device. Our Activation Lock management page covers both directions.
Further reading

Managing Macs for Indian Businesses: 2026 Complete Guide
Macs are arriving in Indian offices faster than IT processes are adapting. Here is how to manage them properly: enrolment, security, apps, patching and support.
Read post
Apple Business Manager Guide for Indian Businesses 2026
Apple Business Manager is the free portal every Apple-using business should have. Here is what it does, what it does not do, and how an Indian company gets set up.
Read post
Zero-Touch iPhone and iPad Deployment for India: 2026 Guide
Ship a sealed iPhone to any city in India and have it configure itself on first boot. Here is how Automated Device Enrollment actually works and how to set it up.
Read postHave a question about this topic?
If you would like help applying any of this to your environment, send us the specifics and an engineer will reply.