to navigate · to open See all results

Apple Business

Connect Apple Business to AssetCenter so the Apple hardware your organization owns arrives with its order number, purchase date and AppleCare coverage already filled in.

Last updated

Apple Business, formerly Apple Business Manager, is Apple's record of every device your organization has bought. Connecting it to AssetCenter means your Macs, iPhones, iPads and Apple TVs arrive with their serial number, order number, purchase date and AppleCare coverage already filled in, rather than being typed in from an invoice.

Apple Business is a purchase record rather than a management service. It knows what you own and how you bought it; it does not know who is signed in on a device or when that device last checked in. The Device Management page also connects Mosyle Business and Jamf Pro, which do report those things, and one device can be linked to both its purchase record and its management service.

Only an AssetCenter account administrator can manage the connection. AssetCenter only reads from Apple Business and never changes anything there.

Device Management is currently in early access and is enabled per organization. If you do not see it under Settings, contact us to have it turned on.

Create an API account in Apple Business

Apple issues the credentials, so this part happens on Apple's site. You need the Organization Administrator role in Apple Business.

  1. Sign in to Apple Business as an Organization Administrator.
  2. Choose Settings, then Integrations, then API.
  3. Press Add API Account and give it a name, such as AssetCenter.
  4. Set Role Access to Device Enrollment Manager. That is the role Apple gives permission to read your devices and device management services, and it is the narrowest one that works. Press Next.
  5. Press Generate & Download to download the private key. It is a .pem file, and Apple generates it only once, so keep it somewhere safe.
  6. Press Edit on the account you just created, and copy the Client ID and the Key ID.

The Client ID and Key ID are only shown behind that Edit button, not on the screen that creates the account, so it is easy to miss them the first time through.

Apple lets you edit what each role can do. If your organization has changed the Device Enrollment Manager role, make sure it kept permission to view device management services, or Apple will refuse to share your devices and the connection will fail.

Connect AssetCenter

  1. Open Settings from the main menu, then Device Management.
  2. Select the Apple Business tab.
  3. Paste in the Client ID and the Key ID.
  4. Leave Team ID blank. Apple issues a single identifier that serves as both, and only organizations Apple gave a separate one need to fill this in.
  5. Open the .pem file in a text editor and paste its entire contents, including the -----BEGIN and -----END lines, into the Private key box.
  6. Decide whether to Look up AppleCare coverage, described below.
  7. Press Connect Apple Business.

AssetCenter checks the credentials with Apple before saving them. If Apple rejects them, the error appears on the form: confirm you copied the Client ID and Key ID from the same API account as the key you downloaded, and that you pasted the whole .pem file.

Once connected, the first import starts in the background. Large organizations take a few minutes.

AppleCare coverage

Look up AppleCare coverage fills in each device's warranty end date and agreement number. Apple requires a separate request for every device, so syncing takes noticeably longer with it on. You can change your mind at any time using the same checkbox on the connected page.

What comes across

For every device your organization owns, AssetCenter records:

  • Serial number, model, model number and Apple's own model identifier.
  • Order number, order date, and who you bought it from.
  • The date the device was added to your organization.
  • Hardware identifiers where Apple has them, such as IMEI, EID and network addresses.
  • AppleCare end date and agreement number, if you turned that on.

Apple does not share what you paid, so purchase prices are still yours to enter.

Apple describes a device with two numbers that both look like model numbers. MTLV3LL/A is the part number, which is what the device itself shows under Settings, General, About and what appears on the box and the invoice; iPhone15,4 is Apple's internal model identifier. An asset's Model Number is filled with the part number where Apple reports one, and the identifier stays on the device record.

The device list

The list below the tabs shows the devices for whichever source is open, so the Apple Business tab lists your Apple Business devices and nothing else. The heading counts them, and the badges beside it count the ones still waiting for a decision.

  • Search matches on device name, serial number, model, order number and user email.
  • Unlinked only hides the devices already attached to an asset.
  • Excluded only shows just the devices you have set aside, described below.
  • Every column heading sorts the list. Press it again to reverse the order.

Matching devices to assets

A device whose serial number matches an asset you already have is linked automatically, on the first sync and on every one after it.

Serial numbers are matched leniently in one specific way. Handheld barcode scanners read Apple's barcode as an S followed by the serial, so an asset created by scanning carries a serial that is one character longer than the one Apple reports. AssetCenter matches with and without that leading S, and once the device is linked the asset's serial number is corrected to the one Apple reports.

Everything else waits for you. For each unlinked device:

  • Import creates a new asset from the device. Choose the category it belongs in, and AssetCenter fills in the manufacturer, model, model number and serial number.
  • Link attaches the device to an asset you already have. Search for the asset by tag, model or serial.
  • Exclude sets the device aside, described below.

Unlink does the opposite of linking. The asset is kept exactly as it is and simply stops being updated from Apple Business.

An asset holds one record per source, so the same Mac can carry both its Apple Business record and its Mosyle or Jamf record at once.

Importing everything at once

Import all deals with the whole waiting list at once. Choose the category each kind of hardware belongs in — computers, phones, tablets and everything else — and confirm. A kind left as None is not imported, and devices already linked to an asset are left alone.

Not everything waiting becomes a new asset. A device whose serial matches an asset you already have is linked to it and updated instead of being added a second time, and the confirmation says how many will go each way before you press anything.

One run creates up to 250 assets, so a large organization takes a few presses; the confirmation tells you when a run will not cover everything. Your plan's asset limit still applies, and if it is reached first the run stops there and says so.

Setting devices aside

An organization's Apple Business record includes everything it has ever bought, including devices that were retired years ago. Rather than importing those, exclude them.

The Exclude button on a device hides it from the list, drops it from the unlinked count, and keeps it out of every import. The device is not deleted, and the exclusion survives future syncs.

Bulk exclude does the same to everything older than a month you choose. Pick a month and year, and AssetCenter tells you how many of the waiting devices were ordered before it. Devices already linked to an asset are never touched, and a device with no order date on record is left alone rather than swept up.

Nothing here is permanent. Turn on Excluded only to see what you set aside, and press the arrow beside any device to put it back in the list.

Importing new devices automatically

Import new devices automatically turns the import around: instead of waiting for you, AssetCenter checks Apple Business every ten minutes and creates assets for devices it has never seen before.

The setting is unavailable until the first sync has finished. Before that, every device counts as new, and turning it on would import your entire purchase history at once.

Choose the category each kind of hardware belongs in:

  • Computers into
  • Phones into
  • Tablets into
  • Everything else into, which covers Apple TVs, Apple Watches and anything else Apple reports.

A kind left as None is never imported on its own. Those devices wait in the list exactly as they do now, so you can have new iPhones filed automatically while every Mac still passes through your hands.

Devices that already exist as assets are linked rather than duplicated: the serial number match runs first, and only what is left over becomes a new asset. Your plan's asset limit applies here too.

Two things arrive later than the asset does. These ten-minute checks read only Apple's device list, never the per-device AppleCare lookup, so a newly imported device gets its warranty on the next daily sync. Everything already on record is left untouched by these checks.

Acquisition and warranty details

When a device is linked to an asset, AssetCenter fills in what the asset is missing:

  • An asset with no acquisition on record gets one from the Apple order, showing the order number and purchase date.
  • An asset with no warranty on record gets one from AppleCare, if you turned that lookup on. Your existing expiring-warranty reminders then apply to it like any other.
  • An asset with no model number on record gets Apple's.

These only ever fill in a gap. If someone has already recorded an acquisition, a warranty or a model number, by hand or through a bulk import, that record is left alone. Apple never overwrites what a person entered.

Manufacturer, model and serial number work the other way round. Apple is the authority on what a device is, so those three are kept in step with what Apple reports.

Keeping it up to date

AssetCenter syncs connected device sources once a day. Press Sync now at any time to run one immediately. Automatic importing adds a lighter check every ten minutes, which looks for new devices and nothing else.

The tab shows the current state at a glance, and the page reports when the last sync finished and whether it succeeded. If Apple stops accepting the credentials, for example because the key was revoked in Apple Business, the connection is flagged and an error explains why. Disconnect, create a fresh API account and connect again to resume.

A device that disappears from Apple Business, because it was released from your organization, is kept on record and marked unavailable rather than deleted, so you can see that an asset's purchase record has gone away.

Disconnect

Press Disconnect and confirm to stop syncing. Assets that were imported or linked are kept, along with their acquisition and warranty history. Only the connection to Apple is removed.

The staged device list goes with it, exclusions included. Connecting again imports the full list from Apple as though for the first time, so anything you had set aside comes back.