Apple Business APIs 2.2: audit organizational units
Apple added organizational-unit support in Apple Business APIs 2.2: list organizational units, retrieve information about a specific unit, and list the user IDs attached to a unit. For an Apple enterprise team, this is not just a documentation detail. It creates a new way to check whether the Apple Business structure still reflects actual sites, departments, countries, purchasing scopes, groups and MDM responsibilities.
1. What Apple officially adds
The Apple Developer changelog states that version 2.2, dated July 15, 2026, adds three Apple Business endpoints for organizational units: get organizational units, get organizational unit information and get user IDs for an organizational unit. Apple Business release notes from July also point to the API account page, where these access rights appear in the permissions table.
Apple shows that this data depends on the View organizational units permission, and that listing users for a unit also requires user visibility. The signal matters: Apple Business automation keeps expanding, but Apple is tying it to a more granular permission model.
2. Why organizational units are becoming critical
In Apple Business, an organizational unit can represent a location, office, legal entity, internal structure, or Apps and Books scope. Apple also explains that apps and books can be provisioned to specific units, and users with specific roles can be assigned to individual units.
In real operations, many issues come from poor alignment: a unit still carrying an old name, a user attached to the wrong scope, a historical content token, incomplete Belgium/France separation, or a local delegation that is no longer documented. The API now lets teams inspect those gaps without relying only on a manual portal review.
3. What does this announcement change for a Belgian or French organization?
For an SMB, the value is keeping a simple but verifiable structure: one or a few units, clear owners, and apps and accounts attached to the right scope. For a mid-market organization, large enterprise or public sector body active in Belgium and France, the issue is broader: separate countries, sites, support functions, service providers, app purchasing and MDM responsibilities without multiplying invisible exceptions.
This announcement mainly improves audit quality. IT leadership can compare Apple Business units with the org chart, HR reference data, Jamf or MDM scopes, user groups and support rules. Security teams can verify that roles and API accounts are not giving a local automation path too broad a view. IT operations can finally treat organizational units as operational data, not as an administrative screen that no one revisits.
4. Underside analysis: connect Apple Business, identity and MDM
Our reading is that organizational units are becoming a control point between identity, apps, devices and operational responsibility. A clean Apple Business tenant is not only about Automated Device Enrollment: it must also show who belongs to which scope, which apps can be distributed, which roles operate locally and which automations are allowed to read that information.
For Underside, the right first use is a read-only audit loop: export units, map users, find naming drift, then compare with Jamf, the MDM platform, the directory and English/French runbooks. Corrective actions should come later, with human validation, because a poorly changed organizational unit can affect purchasing, apps, roles and support.
5. Recommended control points
- Inventory Apple Business organizational units and verify that they still match the sites, countries or entities actually in operation.
- Compare user IDs attached to each unit with the directory, IdP, Jamf or MDM groups and support responsibilities.
- Limit API accounts to readable, justified and documented permissions, especially when user visibility is required.
- Document English/French naming conventions to avoid inconsistent variants between Belgium, France and international teams.
- Connect units to apps, books, content tokens, Blueprints, groups and deployment workflows before any corrective automation.
- Keep audit evidence for security, compliance and partner-delegation reviews.
Goal: turn Apple Business organizational units into usable reference data for audit, MDM integrations, identity and Belgium/France support.
Audit your Apple Business governanceApple sources: Apple School Manager and Apple Business APIs changelog, Create an API account in Apple Business, Configure organizational units in Apple Business, and Apple Business release notes.