Apple @ Work: How zero-touch enrollment killed the market for stolen corporate devices
Apple Business Manager and Automated Device Enrollment now make stolen managed Macs and iPads hard to resell, sharply reducing theft profits.
Intelligence analysis by GPT-5.4 Mini

The piece argues that Apple’s zero-touch enrollment and managed Activation Lock have changed corporate device theft from a profitable resale market into a low-value parts game. For IT teams, that means less hardware loss and more confidence that stolen devices are effectively unusable.
Apple made some work computers act like they still belong to their company even after someone erases them. It is like stealing a bike, only to find the lock is still glued to it when trying to sell it.
Analysis
What changed
The article says the old theft model was simple: steal a laptop or tablet, wipe it, reinstall the operating system, and resell it. That worked because the hardware could be turned into a clean, anonymous machine once the disk was erased.
Why Apple’s approach matters
According to the piece, Apple Business Manager and Automated Device Enrollment changed that by linking a device’s serial number to an organization at activation time. When a company assigns that serial number to its management platform, the device checks in with Apple during setup and pulls down the company’s profiles, apps, and security policies automatically.
That same workflow becomes a deterrent after theft. The article explains that if someone wipes a managed MacBook and tries to set it up again, the machine connects to Apple and is met with a Remote Management screen that asks for corporate credentials. The author says there is no practical bypass at that stage. Combined with managed Activation Lock, the device becomes effectively unusable for a thief and unattractive to a buyer who knows what they are looking at.
The practical outcome
The article’s main claim is not that theft disappears, but that the economics change. Instead of selling a fully functional computer, a thief is left with a much less valuable pile of parts. For IT teams, the upside is twofold: FileVault helps protect the data, and Apple’s enrollment system helps protect the hardware from being casually repurposed.
The author closes by warning that organizations that buy devices at retail and manage them manually do not get the same server-level ownership protections. In that setup, the hardware remains more exposed than devices purchased through Apple Business or an authorized enterprise reseller.
Key points
- The article says stolen corporate Macs and iPads used to be easy to wipe and resell.
- Apple Business Manager and Automated Device Enrollment now tie device identity to an organization at activation.
- A wiped managed Mac can hit a Remote Management screen during setup and require corporate credentials.
- Managed Activation Lock further reduces the value of stolen devices.
- The author argues the real remaining value is in parts, not in reselling a working machine.
If more organizations use Apple Business with Automated Device Enrollment, stolen Macs and iPads become much less useful to thieves. That can lower hardware losses and reduce the chance that stolen corporate devices re-enter the resale market.
The protection depends on companies actually using Apple Business and automated enrollment. Devices bought and managed outside that system remain more exposed, and thieves may still make money by stripping them for parts.



