Apple Business Essentials now available for small businesses
apple.com
apple.com
As a one man band, this basically means I cannot use Apple Business Essentials unless I lie/make up details during the application process (which includes phone verification with a real Apple human - so this is not a trivial thing to bypass).
Utterly baffling, as I could really use some of the features of this program, but I can’t.
This doesn’t just affect me. I work with larger companies on IT projects so am in a position to advocate (or not) for products and services, and so this is one I will obviously not be recommending if I can’t get into it myself!
Edit: one of the things I was trying to achieve was to setup some way to buy apps on the App Store under my company (different card and billing address etc), which presumably needs a separate Apple ID. At the moment I normally have to buy apps outside of the App Store (where possible) in order to be able to pay with my company rather than personal details (important for tax/accounting etc for business expenses).
Does anyone have a solution (as a sole trader) for running two Apple IDs, one for personal and one for business?
That seemed to do the trick.
One thing to take note of though is be very careful if you set up managed IDs and a verified domain through Apple Business Essentials. It locks devices down pretty heavily. I'm not familiar with this area of IT and didn't know that, although it might be pretty obvious to those who work in the space.
One common but sophisticated attack involves getting your victims to install your own MDM certificate on their machines, because you've convinced them that they're getting some sort of free lunch. After they install your MDM certificate, you own their machines, and you can do anything with them that you want -- make them into your own private bot army to rope in more victims, or whatever.
But if the devices in question already have an MDM certificate installed, that prevents this kind of attack.
Running my own MDM profile also means that I can ensure that my wife's devices are always up to date, because I can enforce this at the MDM level. And that's an important issue for her employer, since her law firm uses BYOD. So, I can use my MDM profile to ensure that all their requirements are met and enforced by my own MDM.
I realize this is basic PR messaging, but it's a weird/ironic take from a company that regularly competes as "the richest company in the world". Usually, Big loves Big. Big companies usually telegraph how Enterprisey they are, how the biggest of the big use their bigly products. But Apple continually messages this inverse relationship. We are the biggest, and we serve the hordes of the little. It's a weird/unusual message.
(and I'm making zero claims as to the credibility of this messaging, just noticing that it's different)
My observation is that Apple's commitment varies a lot from year to year, and especially from city to city.
Chicago was great. Seattle (well, Bellevue) not at all.
Apple is good at making individuals want to use their products for work, where as Microsoft is good at making workplaces use their products, so consumers know their OS and choose it for home. Different ideologies.
Which is: Apple is really not a business-user focused company. Windows-based PCs have long dominated the business world. And as someone who does use Macs for both personal use and at work, setting up a work computer is always an awkward, sup-par experience. There are so many features (like iMessage, Facetime, and iCloud) that are exclusively designed for personal use, and no good way to e.g. configure which parts of my personal data should be available on my work computer. Or I can use a totally separate apple id on my work computer, but then I can't get access to things like my Apple Music account that I am subscribed to on my personal account.
If the devices are managed (in an MDM) then the assumption should be that anything and everything happening on the device can be seen at any time. The conundrum is that Mac OS is such a personal user-centric operating system that it appears to be difficult for users not to take advantage of those features. It's almost like when you put a treat in front of someone - even if they didn't want it before, once it's right in front of them they suddenly want it.
Edit: Clarification / expounding
At best, they understand the workgroup market reasonably well. Anything above the workgroup is an alien concept to them.
Apple is nothing but a massive collection of workgroups, and workgroups of workgroups.
This is huge, especially if it will work easily without the need for intermediary identity services to make it all work.
I might also be mis-remembering this, it's been a hot minute since I've dealt with this stuff.
Just to temper your expectations, I don't believe they're talking about signing into Apple devices using Google identity services directly. Google identity services (and other identity providers) can be used to provision managed Apple ID's that can be used to log into the devices. It's basically just pulling the username from LDAP and creating a <username@yourcompany.appleid.com> account that can be used in place of your normal Apple ID. All of the accounts created this way will still reside in Apple Business Manager / on Apple's servers, so if you disconnected the IdP connection Google would have no power there.
We ended up going with a small MDM vendor, which was just barely passable enough to compliantly manage a fleet of Macs with somewhat minimal time investment. Still, it came with fully employee spy mode turned on (website monitoring on by default) and had promised features, such as FDE key escrow, that barely ever worked in practice.
So thank god for Apple Business Essentials, this is a blessing for every startup that runs a fleet of Macs.
Anecdotal, but I recently picked Jamf over Essentials for a ~30 person company because Essentials was just too limited. I really, really wanted it to work. Not having another company involved felt so nice. But I just couldn't do most of what I needed.
They have been adding features, but it's still way, way short of what Jamf can do. Particularly around enrollment options, although it seems they've finally added the ability to do user-based enrollment without wiping the machine?
Do I have that right and is it available with Business Essentials, does anyone know?