A new hire in Pune opens a sealed box shipped from your supplier. Ten minutes later they are working.
Zero-touch deployment means a Mac or iPhone ships direct to the person who will use it, configures itself the moment it connects to the internet, and arrives fully managed with the right apps, settings and identity already in place. No imaging, no courier loop through head office, no technician time per device. The capability is free with an Apple Business account; what makes or breaks it is one procurement decision. Remote-first from Gachibowli, Hyderabad, for organisations across India.

- Sealed boxShips direct to the user, any city
- First bootConfiguration applied automatically
- Zero hoursTechnician time per device
- Buy rightThe one decision that enables it all
Eight links, and the whole thing depends on getting the first one right.
Buy through a channel that registers the device to you
This decision happens before anything technical, and the entire chain rests on it. A device bought through a reseller or carrier able to register it to your organisation appears in your Apple Business account automatically, and the association is permanent. A device bought off a retail shelf or an online marketplace does not, and no amount of configuration afterwards fully recovers that. It cannot be fixed properly later, which is why it comes first.
An Apple Business account holding the device records
The account is free and it is the register of which devices belong to your organisation. It also holds your Managed Apple Accounts, your app purchases and your management service connections. Without it there is nothing for a device to enrol into on first boot, so an organisation with no account has no route to zero-touch regardless of how good its MDM is.
A management service connected to that account
Intune, Jamf, or the device management built into Apple Business itself. Apple documentation is explicit that more than one service can be connected, with devices assigned between them as needed, so an estate running Intune for most devices and Jamf for a creative team is supported rather than a workaround.
Blueprints, so configuration arrives with the device
A Blueprint is a preconfigured bundle of settings and apps assigned to devices or a user group; Apple describes the model as configure once, deploy everywhere. It is what turns enrolment into a finished device rather than a managed but empty one. Assign the sales Blueprint and every new sales hire gets the same applications and configuration without anybody deciding it again.
Identity, so the user signs in as themselves
Managed Apple Accounts federated with your existing directory mean the person signs in with credentials they already have rather than creating a personal Apple Account on a company device. Apple names Microsoft Entra ID and Google Workspace among the supported identity providers. This is what stops a company MacBook ending up attached to somebody personal iCloud, the classic cause of an unrecoverable device.
Supervision, which makes management stick
A device enrolled through this route is supervised, a stronger state than a device that merely has a management profile installed. Supervision enables the controls organisations actually need, and it survives the device being erased. That durability is the practical difference between managing a device and hoping it stays managed.
Apps that arrive without an App Store password
Applications bought by the organisation and assigned through the account install without personal credentials, and the licences stay the property of the organisation. A new starter is never blocked waiting for an install to be authorised, and a leaver does not walk away with software you paid for.
It works wherever in India the person is
The device configures itself on any internet connection. A hire in Pune, a field engineer in Coimbatore or a new office in Gurugram can receive a sealed device directly and be productive without the hardware ever passing through your head office. For distributed Indian organisations this is where zero-touch stops being a convenience and becomes the reason the operating model works at all.
Where you buy the device decides whether you can ever deploy it this way.
We raise this on every Apple engagement because it is the only decision in this area that is genuinely hard to reverse, and it is almost always made by somebody who has never heard of any of this.
- A device bought through a reseller or carrier that registers it to your organisation is permanently associated with you. It enrols itself on first boot, stays enrolled through an erase, and the association is not something a user can remove. This state costs nothing extra, provided somebody asks for it at the point of purchase.
- A device bought from a retail store or a marketplace can still be added afterwards with Apple Configurator, which Apple supports for iPhone, iPad, Mac, Apple TV models with Ethernet, and Apple Vision Pro. Devices added this way do become supervised and enrolled. But Apple gives the user a 30-day provisional period during which they can release the device from your organisation, your supervision and your management service entirely.
- That 30-day release window is the whole difference, and why we do not treat Configurator as an equivalent path. For a device issued to a trusted employee it may never matter. For a contractor, a departing employee, or anyone with a reason to prefer the device stayed personal, it is a door a properly purchased device simply does not have.
- The practical rule: procurement, finance and office administration all buy through a channel that registers devices to your organisation, always, including urgent one-off purchases. The emergency MacBook bought at a mall in Bengaluru on a Thursday afternoon is the one that surfaces in an audit two years later.
Four things that decide whether this works in practice.
We fix the procurement side, which is where it actually fails
Almost every failed zero-touch setup we see is technically fine and procedurally broken: devices still being bought through channels that cannot register them, usually by people who were never told. We work with your finance and admin functions to establish one route, including a fast path for urgent purchases, because without that the chain breaks quietly and repeatedly.
We test the first-run experience on real hardware
A configuration that looks correct in a console can still produce a confusing first boot: a prompt in the wrong order, an app that needs something not yet installed, a conflicting setting. We run a real device through the whole sequence exactly as a new starter would, which finds these before a new hire does on their first morning.
We build the leaver half as well as the starter half
Zero-touch onboarding gets the attention because it is visible. The part that costs money quietly is the other end: devices not recovered, licences still assigned to people who left, hardware attached to personal Apple Accounts in a cupboard. We build both halves, because an onboarding flow without a matching offboarding flow degrades within a year.
Remote-first from Hyderabad, reachable on the morning it matters
A new starter whose device will not complete setup is urgent in practice whatever the ticket says, because somebody senior is standing next to them. We deliver remotely from Gachibowli, Hyderabad to organisations across India, managed clients get a 30 minutes response SLA, and you get a contact who knows how your Blueprints are built.
Six Indian situations where zero-touch changes the maths.
A company hiring in bursts
Fifteen people starting the same Monday is a real problem when each device needs a technician for two hours. With zero-touch the fifteenth device costs exactly what the first did, which is nothing. Growing Indian firms and GCC ramp-ups tend to adopt this at the point where a hiring wave has just gone badly.
Teams spread across cities
A hire in Mumbai, a support engineer in Kochi, a new branch in Jaipur. Shipping a sealed device directly and having it configure itself removes the entire logistics loop of routing hardware through a head office and back out, which for distributed organisations is usually the difference between a productive first week and a wasted one.
Firms whose clients audit their device controls
IT services, BPO and consulting firms answering enterprise security questionnaires need to show encryption, passcode policy and management coverage enforced from the first minute of a device life. Zero-touch means there is no window during which a device was in use and unmanaged, which is a materially better evidence position.
Retail, hospitality and site operations
iPads for billing, kiosk use, inventory or guest experience across many outlets where nobody on site is technical. Devices arrive at the store, connect, and configure themselves into the right role. Replacing a broken one becomes a courier job rather than an engineer visit, which changes the economics of running devices across a chain.
Organisations losing devices to personal Apple Accounts
The recurring Indian pattern: a company MacBook set up in a hurry with an employee personal iCloud, and two years later a leaver dispute over a device nobody can recover. Organisation-registered devices with Managed Apple Accounts federated to Entra ID remove the failure mode at the root.
Any organisation where IT is one person
When device setup competes with everything else on one person list, it is the task that slips, and new starters wait. Removing it entirely gives back hours spent on work that produces nothing distinctive. For small Indian firms this is frequently the highest-return change available in the whole estate.
The same new starter, under three different setups.
| Feature | Zero-touch | Managed, but manual | Unmanaged |
|---|---|---|---|
Device can ship direct to the user | |||
Technician time before handover | None | One to three hours | None |
Device ready on day one | If IT had notice | Rarely | |
Same configuration every time | Depends who built it | ||
Apps install without personal credentials | Sometimes | ||
Works for a hire in another city | Poorly | Unmanaged | |
Encryption enforced from the start | If remembered | ||
Recoverable if the person leaves abruptly | Usually | Often not | |
Evidence for an auditor or client questionnaire | Partial | ||
Effort to onboard the fiftieth person | Same as the first | Fifty times the first | Chaos |
What each route actually gives you.
| Registered at purchase | Added via Configurator | Not enrolled at all | |
|---|---|---|---|
| Device configures itself on first boot | Yes | After manual preparation | No |
| Ships sealed direct to the user | Yes | No, needs handling first | Yes, unmanaged |
| Becomes supervised | Yes | Yes | No |
| User can release it from your organisation | No | Yes, within 30 days | Not applicable |
| Association survives an erase | Yes | After the provisional period | No |
| Blueprints and configuration apply automatically | Yes | Yes | No |
| Organisation-owned app licences | Yes | Yes | No |
| Recoverable when an employee leaves | Yes | Usually | Often not |
| Technician time per device | None | Meaningful | None, and it is unmanaged |
| Suitable for a hire in another city | Yes | Difficult | Not really |
| How most Indian urgent purchases are made | Rarely | Sometimes | Usually |
Five steps from purchase order to sealed-box handover.
- 1
Audit how devices are actually being bought
Week 1
Not the policy, the reality. We look at where the last year of Apple purchases came from, which of them are in the account and which are not, and who in the business can buy hardware. This nearly always reveals more purchasing routes than anybody expected, and that is the finding that matters most.
- 2
Establish one route, with an urgent path
Week 1-2
A named reseller able to register devices to your organisation, agreed with finance and communicated to everybody who can raise a purchase. Critically, a fast route for urgent needs, because a policy that makes the correct route slower than a trip to a mall will be bypassed within a month.
- 3
Build and test Blueprints per role
Week 2-3
One configuration per common role rather than one for everybody, because a designer, a salesperson and a finance user need genuinely different software. Each is tested end to end on a real device, going through the exact sequence a new starter will see, until the first-run experience is clean.
- 4
Reconcile the existing estate
Week 3-4
Devices already in circulation are matched against the account. Anything missing is assessed: some can be added through Apple Configurator, accepting the 30-day provisional release window, and some are better left as they are and replaced on their natural cycle. We tell you which is which rather than adding everything indiscriminately.
- 5
Document and hand over, or run it
Continuous
A short written process covering how a device is requested, bought, shipped, configured and recovered, plus the starter guide that ships with each box. You can run this yourself, and many organisations do. Where there is no internal capacity we operate it under a managed contract with a 30 minutes response SLA.
The questions Indian IT leads ask before committing to this.
Fifteen checks before you promise anybody a sealed-box handover.
Procurement, where it is decided
- Does everyone who can buy a device know the rule?Finance, admin and department heads, not only IT.
- Is there a named reseller who registers devices to you?One channel, consistently, is far easier to govern than four.
- Is there an approved route for an urgent purchase?Without one, somebody will go to a retail store. Every time.
- Do purchase orders record the serial numbers?Reconciliation later is impossible without them.
- Do you know which devices were bought outside this route?The gap is nearly always larger than expected.
The technical chain
- Apple Business account exists with two or more administratorsA single administrator is a standing risk.
- Your management service is connected and devices default to itA device assigned to nothing enrols into nothing.
- At least one Blueprint exists per common roleEnrolment alone gives a managed but empty device.
- Identity federation configured, or a clear reason it is notStops personal Apple Accounts on company hardware.
- Apps purchased at organisation level and assigned to groupsNobody should need a personal password for work software.
The human part
- A one-page starter guide ships with the deviceWhat they will see, what to do, who to contact.
- The Blueprint is tested on a real device firstConsole review does not catch what a first run does.
- Somebody is reachable on day one for the first-login questionThere is always one, and it is always small.
- A defined process for a device that arrives faultyIt happens, and a new hire cannot wait a week.
- A leaver process that recovers the device and licencesThe half of the lifecycle people skip.
The layers this depends on.
Apple device management India
The whole picture: account layer, management platform, security, and the disciplines that keep an estate managed.
Learn moreManaged Apple Accounts
The organisation-owned identity layer that keeps personal iCloud off company hardware.
Learn moreApple Configurator
The Mac tool for adding devices bought outside the channel, and the 30-day provisional window that comes with it.
Learn moreTell us where your last ten Apple devices were bought.
That one answer tells us most of what we need to know about whether zero-touch is available to you today, what it would take to get there, and how much of your existing estate can be brought along. It is a short conversation and it usually surfaces something worth knowing. Initial reply within 4 business hours.