Cybersecurity
Secure File Sharing: What Is It and Why Is It Important?
Patrick Sullivan

If you manage Macs and iPhones for your business, there’s a good chance the single most powerful login in your company is protected by the same 6-digit code you’d get for resetting a food delivery app password. That login belongs to Apple Business Manager, and it’s worth understanding exactly what it controls before we get into the gap.
Apple Business Manager is Apple’s web-based portal for businesses to manage every Apple device they own from one place. It’s where IT admins enroll new Macs and iPhones automatically, push apps and configurations without touching each device by hand, and manage the Managed Apple Accounts your team uses to sign in. If your company has more than a handful of Apple devices, ABM is almost certainly running quietly in the background of how they’re deployed and controlled.
That’s exactly why the account that logs into it deserves more attention than it usually gets.
Here’s the part that catches most business owners off guard. Apple has spent the last several years pushing its own users toward passkeys, a login method built to resist phishing because there’s no code to steal or trick someone into typing in. Personal Apple IDs already have access to this.
Apple Business Manager admin accounts, the ones that manage every device your company owns, have lagged behind. Computerworld has reported directly on this exact gap: ABM admin accounts sign in using Apple’s standard two-factor authentication, typically a trusted device or a trusted phone number via SMS or voice, and lack the federated authentication, passkey, and hardware security key (FIDO2) options already available elsewhere in Apple’s ecosystem. An admin account with authority over thousands of devices can still be protected by nothing more than SMS-based two-factor authentication, a text message with a 6-digit code.
Put plainly: the account managing your entire fleet is currently offered less protection than an average person’s personal iPhone.
SMS codes are one of the more exploitable forms of two-factor authentication. They can be intercepted, phished through a fake login page, or bypassed entirely through SIM swapping, where an attacker convinces a carrier to move your phone number to their device. None of that requires advanced hacking. It requires a convincing phone call and a target worth the effort, and a company’s ABM admin login is exactly that kind of target.
It’s tempting to file this under “one more security setting to fix eventually.” We’d push back on that.
Every Mac and iPhone your company owns is tied to Apple Business Manager. Someone with access to that admin account can push configurations, reassign devices, and reach into the accounts your team uses every day. A single compromised login can turn into a fleet-wide problem fast.
| Personal Apple ID | Apple Business Manager admin | |
|---|---|---|
| Passkey support | Yes | Not yet standard |
| Blast radius if compromised | One person’s data | Every enrolled device and account |
| Typical protection in practice | Often upgraded to passkeys | Frequently still SMS-based 2FA |
| Who notices if it’s weak | The individual | Nobody, until something goes wrong |
Most managed IT providers treat Apple devices as an afterthought, something to tolerate alongside a Windows-first environment, not something they’ve actually built expertise around. That’s a real problem, because Mac and iPhone deployments have their own management tools, their own account structures, and their own blind spots, and Apple Business Manager’s authentication gap is a perfect example of one that goes unnoticed by a provider who isn’t paying close attention to the Apple side of the business.
We go beyond the call here: we’re geeky and freaky about security, on Apple’s side of the house as much as anywhere else. Parachute has held SOC 2 Type 2 certification, the independent audit that verifies, over time rather than as a one-time snapshot, how well a company protects client data, for 7 consecutive years, a credential held by fewer than 5% of MSPs, and that same rigor is what we bring to something as specific as an admin account’s authentication settings. Closing this exact gap is the kind of routine housekeeping we handle before it becomes a headline.
Apple Business Manager is Apple’s web portal for businesses to manage their Apple devices at scale: enrolling new Macs and iPhones automatically, distributing apps and settings, and managing the accounts employees use to sign in, all from one admin console.
Apple Business Manager itself is a secure platform, but the security of any individual company’s setup depends on how admin accounts are protected. Accounts still relying on SMS-based two-factor authentication carry more risk than accounts using stronger available methods, since SMS codes can be phished or intercepted.
Passkey support for Apple Business Manager admin accounts has lagged behind what’s available for personal Apple IDs. Businesses should use the strongest authentication method currently available in ABM and revisit their settings regularly, since Apple continues to expand what’s offered.
Because ABM controls every enrolled device and the accounts tied to them, a compromised admin login can give an attacker the ability to reconfigure devices, reassign them, or access company accounts at scale, well beyond one person’s information.
Schedule a call with someone who’s actually helpful, and we’ll walk your Apple Business Manager setup end to end (admin accounts, device enrollment, the works) and tell you exactly where you stand -> https://parachute.cloud/free-consultation/