Managing Macs in a business environment comes with its own vocabulary. Here is the field glossary we hand to IT managers who are integrating Apple devices into their fleet.
- MDM (Mobile Device Management)
- The framework for centrally configuring, securing, and managing Apple devices: the foundation of every serious Mac deployment.
- Automated Device Enrollment (formerly DEP)
- Apple’s program for automatically enrolling company-owned devices into your MDM the moment they are unboxed.
- Apps & Books (formerly VPP)
- Volume purchasing and automated app deployment for macOS and iOS via MDM.
- Supervision
- The elevated management state for organization-owned devices, enabling deeper controls than personally-owned enrollment.
- FileVault
- Built-in full-disk encryption for Mac, the counterpart of BitLocker on Windows. Non-negotiable for business laptops.
- Gatekeeper & notarization
- macOS security features that verify apps are signed and checked by Apple before they run.
- System Integrity Protection (SIP)
- Prevents modification of the operating system itself, even by administrators.
- Configuration profiles
- XML payloads pushed by MDM that enforce settings: password policies, Wi-Fi and 802.1x, certificates, restrictions.
- Platform SSO
- Modern single sign-on that binds a Mac login to your identity provider (Microsoft Entra ID, Okta), the modern replacement for legacy Active Directory binding.
- Declarative device management
- Apple’s current management architecture: devices apply and report state autonomously rather than waiting for server commands.
- Keychain
- Encrypted storage for passwords, notes, and certificates. Similar to Credential Manager on Windows.
If your firm is adding Macs and wants them managed to the same standard as your Windows fleet, this is a conversation we have with clients weekly.