Apple Business: audit Activation Lock and access changes
Recent Apple Business updates let teams make device return and administrative changes verifiable: Activation Lock status through the API and an expanded audit log.
1. Separate lock status from removing the lock
Apple has added retrieval of Activation Lock status through the Apple Business API. It does not replace the permissions or process used to remove the lock. Instead, it lets teams establish whether a device requires attention before return, repair, or reassignment. It is a read control to place between inventory, MDM, and the support ticket.
2. Put audit events into a runbook
The September 23 update expands the audit-event scope. Teams can link changes to roles, partner access, and administration to a request, owner, and review date. A regular export is useful; automation that changes the tenant without evidence of control is not.
3. An operating loop for Belgium and France
- Compare Activation Lock status with return inventory before a maintenance decision.
- Associate each discrepancy with a device, named owner, and ticket.
- Retain audit events when changing provider or role.
- Review API access under least privilege.
For Apple enterprise services in Belgium or Apple enterprise services in France, this method connects security, support, and lifecycle management without conflating Apple Business with MDM.
Goal: turn Activation Lock status and the Apple Business audit log into useful support-control evidence.
Structure your Apple Business governanceOfficial source: Apple Business release notes, updated September 16 and 23, 2026.