By method
| Method | When to use | Compatibility | Driven by | Pros | Cons |
|---|---|---|---|---|---|
| Zero Touch | Gold standard - move towards this little by little | ✅ macOS ✅ Windows ✅ iOS/iPadOS ❌ Android (coming soon) | Admin |
|
|
| Employee enrollment (default) | Default - always works! | ✅ macOS ✅ Windows ✅ Linux ✅ iOS/iPadOS ✅ Android | Employee |
|
|
| Account-driven Device Enrollment | If you federate accounts in Apple Business | ❌ macOS (coming soon) ✅ iOS/iPadOS | Employee |
|
|
| Silent agent deployment | If you already can deploy packages (migration scenario) | ✅ macOS ✅ Windows ✅ Linux | Admin |
|
|
| Migrating with Apple Business | For devices in Apple Business and on macOS Tahoe 26+ | ✅ macOS ✅ iOS/iPadOS | Admin |
|
|
By platform
macOS
- Zero Touch — gold standard; use this for new devices purchased through Primo or an authorized reseller
- Migrating with Apple Business — for devices already assigned in Apple Business running macOS Tahoe 26+
- Silent agent deployment — if you already have a package deployment tool and need to migrate silently
- Employee enrollment — always works as a fallback; relies on employee action
Windows
- Zero Touch — gold standard; use this for new devices enrolled via Windows Autopilot
- Silent agent deployment — if you already have a package deployment tool and need to migrate silently
- Employee enrollment — always works as a fallback; relies on employee action
Linux
- Silent agent deployment — preferred if you have a package deployment tool
- Employee enrollment — always works; relies on employee action
iOS / iPadOS
- Zero Touch — gold standard; use this for devices purchased through Primo or an authorized reseller and assigned in Apple Business
- Migrating with Apple Business — for devices already assigned in Apple Business
- Account-driven Device Enrollment — if you federate accounts in Apple Business and want to preserve privacy on personal devices
- Employee enrollment — always works as a fallback; relies on employee action
Android
- Employee enrollment — the only available method; employees enroll their own devices