Zero-touch deployment — ABM, ADE and MDM enrolment

The employee opens the box, connects to their wifi, signs in, and the laptop configures itself into your management, with your apps and your policies. Nobody from IT touches it. Nobody talks them through a setup call. It works because the device was already yours before it was posted.

What zero-touch actually means

Also called no-touch or out-of-box enrolment. The device’s hardware identity is registered to your organisation BEFORE it reaches the person, so the first time it starts up it asks your management server what it should be — rather than asking the employee, who then has to be walked through it.

The difference matters most exactly where GreyFusion works: a new hire in a country where you have no IT staff, no office and nobody who can sit with them for an hour. Zero-touch turns that hour into a five-minute self-setup that cannot be done wrong.

The three things people mix up

ABM, ADE and MDM get used interchangeably and they are three different layers. Getting them in the right order is most of what this work is.

  • ABM — Apple Business Manager. Your organisation’s account with Apple. It is where devices, app licences and Managed Apple Accounts live.
  • ADE — Automated Device Enrollment, the part of ABM that binds a serial number to your MDM so enrolment happens at first start-up and cannot be skipped.
  • MDM — the management server itself (Jamf, Intune, Kandji, Mosyle and the rest). It holds the policies, the apps and the configuration profiles.
  • Supervision — what ADE-enrolled Apple devices get, and what makes the strong management controls available at all.

How a device gets into your ABM — and why the route matters

GreyFusion buys through Apple’s authorised distribution for the region, which is what makes the good route available: a device bought through a reseller whose details are registered in your Apple Business Manager is added to your ABM at the point of supply, by serial or IMEI, and stays yours permanently. Nobody can release it.

The other route is a device added afterwards with Apple Configurator. It works, and it is how an existing fleet gets brought in — but Apple gives the user a provisional window in which they may release it from management, so it is not the same promise. Which route applies to a given batch is stated rather than assumed.

  • Apple → authorised regional distribution → GreyFusion → your ABM → your MDM → your employee
  • Bought through the channel: in your ABM at supply, permanently, by serial or IMEI
  • Brought in afterwards: added with Apple Configurator, with Apple’s provisional release window

What happens, in order

From purchase order to a working laptop, with nobody from your IT team touching the machine and nobody walking the employee through a setup call.

  • The device is sourced through the official Apple supply chain
  • Its serial or IMEI is associated with your Apple Business Manager
  • It is assigned to your MDM inside ABM, so enrolment is automatic and cannot be skipped
  • GreyFusion completes the pre-deployment enrolment and configuration
  • It ships directly to the employee, wherever they are in Nigeria
  • They turn it on and connect to wifi or cellular
  • Apple’s activation recognises the device as your organisation’s
  • Your management profile is applied and enforced
  • Your MDM pushes apps, policies, restrictions, certificates, wifi and VPN

Windows, and the same idea

The Windows equivalent is Windows Autopilot: the machine’s hardware hash is registered to your tenant so it joins your management at first start-up instead of being set up by hand. The principle is identical — the identity is registered before the box is opened — and the practical constraints differ by hardware vendor and purchase channel. Tell us which vendor and we will tell you what is possible for that hardware.

Devices that arrive belonging to somebody else

A second-hand or transferred machine often turns up still enrolled in a previous owner’s management, still carrying an activation lock, or still holding a firmware PIN nobody at your company knows. Until those are cleared it is not your device in any useful sense.

GreyFusion records each lock separately — MDM, Find My and PIN — with who checked it, when, and what the evidence was, because a compliance record nobody can attribute is worth very little when it is later questioned. Clearing them is part of the data-erasure step and is not billed separately.

What the record carries

Per device: the serial checked against Apple’s records, the enrolment status, which MDM tenant it belongs to, whether it was released from a previous one, and the date. It sits on the same device record as the purchase, the delivery and — eventually — the erasure.

Questions we get asked

What is the difference between ABM, ADE and MDM?
ABM is your organisation’s account with Apple. ADE is the feature inside it that binds a device serial to your MDM so enrolment happens automatically at first start-up. MDM is the management server that then applies your policies and apps.
Can you add devices to our ABM at the point of purchase?
Yes. GreyFusion buys through Apple’s authorised distribution, so a device bought through us is associated with your Apple Business Manager by serial or IMEI at supply and assigned to your MDM before it ships.
Can you enrol devices we already own?
Usually yes, but the route matters. A device added to ABM after purchase via Apple Configurator carries a provisional period in which the user can release it; a device added through the reseller channel at purchase does not. We will tell you which applies to your devices.
What if a device is still locked to a previous owner?
It is recorded as such and the release is chased — MDM, Find My and firmware PIN are tracked separately, each with the person who checked it and the evidence. Clearing them is part of data erasure and is not a separate charge.
Which MDM platforms do you work with?
Whichever one you already run — Jamf, Intune, Kandji, Mosyle and the others all take the same shape from our side: your serials, bound to your tenant, before the device ships.

Read next

Zero-Touch Deployment: ABM, ADE and MDM Enrolment