Today’s dashboard update connects Watchman Monitoring to Apple Business Manager and Apple School Manager. Once a connection is in place, the Macs you already monitor pick up their purchase history, AppleCare coverage, and MDM enrollment state
directly from Apple.
No agent update is required, and nothing is installed on the Macs. This is a dashboard feature that reads from Apple’s API on your behalf.
One thing to be clear about up front, because it shapes everything else: this integration enriches Macs you already monitor rather than adding new ones. Devices are matched to your existing records by serial number, so a Mac needs the Watchman Monitoring agent to receive Apple’s data. That is a deliberate choice — the agent is the thing that knows whether a Mac is alive, and we did not want an hourly API sync quietly making a dead machine look like it checked in.
AppleCare and warranty dates, from Apple
Warranty coverage now comes from Apple’s own record: coverage type, start and end dates, agreement number, and payment type. These land on the Mac’s page and flow into the expiration notices you already receive, so an AppleCare plan expiring in sixty days reaches you the same way every other tracked expiration does.

We also read Apple’s own verdict on whether a plan is live, which matters more than it sounds. A plan Apple has cancelled — a returned machine, a refunded agreement — can still have an end date months in the future. Reading the date alone would tell a client their Mac is covered when it isn’t. Cancelled coverage is recorded as cancelled.
Coverage entries created by this integration are kept separate from everything else. Warranty rows from other sources are never modified or removed, and any entry you have manually overridden is left exactly as you set it.
Enrollment, without a second opinion
For each matched Mac, the dashboard now shows whether it is assigned to an MDM server in Apple Business Manager, and which one. Macs assigned to Apple Configurator rather than a third-party MDM are identified as such. Macs that are in Apple Business Manager but assigned to no MDM at all are flagged.

This is displayed as information, not as an alert. Your Macs already report their real enrollment state through the MDM Enrollment plugin, which sees what is actually on the machine — profiles, DDM, user-approved status. Adding a second enrollment alert sourced from Apple’s side of the fence would mean two things telling you about one condition, and disagreeing at the edges. What Apple Business Manager adds here is the organizational view: what Apple thinks should be true.
Where these Macs came from
Apple knows things about your clients’ Macs that the machines themselves do not: order number, order date, the reseller they were purchased through, part number, and the date each was added to the organization. That is now on the Mac’s page, along with Apple’s own model name — “MacBook Pro (16-inch, 2023)” rather than Mac14,6 — plus color and storage capacity.
There is also a purchase report per connection, grouping a client’s Macs by where they were bought. It answers “who supplies this client’s hardware, and how much of it” without a spreadsheet.
The Macs you aren’t monitoring
Every connection produces a list of Macs in Apple Business Manager with no Watchman Monitoring agent.

This is the part no on-device plugin can tell you, by definition — an agent that was never installed cannot report that it is missing. If a client bought fifteen Macs last quarter and you are monitoring eleven, that gap has been invisible until now. It shows up here with serial numbers and the date each was added to Apple.
Non-Mac devices in the organization — iPhones, iPads — appear in this list too. This release targets the Mac population, and we would rather show you everything Apple returned than silently filter it.
Sync behavior, and why coverage is slower
Each connection syncs every hour. Device, enrollment, and purchase data all refresh on that cadence.
AppleCare coverage is deliberately slower. Apple rate-limits coverage lookups hard — we measured roughly seventeen requests per minute before throttling, with a sixty-second penalty — and coverage dates change on the order of years, not hours.
So coverage refreshes at most once every 24 hours per Mac, capped per sync, least-recently-checked first. A large fleet converges over successive syncs instead of spending its entire sync window asleep waiting on Apple.
When you need an answer right now, a Mac’s page has Refresh from Apple…, which fetches that single machine’s current warranty and enrollment state immediately. Only that computer is touched.
ABM fields are also available as columns in the Computers CSV export, if you would rather work with the whole fleet at once.
Setting it up
You will need the Organization Administrator role in Apple Business Manager, since only that role can create an API account.
In Apple Business Manager, go to Settings → API, select Add API Account, and give it a role — Device Enrollment Manager is sufficient, and is the least access this integration can work with. Choose Generate & Download for the private key, then
open Edit on the account to copy the Client ID and Key ID.
In your dashboard, go to Integrations → Apple Business Manager, click Connect an Apple Business Manager, and paste those three values in. Apple School Manager is selected from the same form. Your private key is encrypted at rest and is never
displayed back after saving.
You can add a connection per client organization; each syncs independently. A connection is not tied to a group, so one organization can enrich Macs across as many groups as you have them in, and enriched Macs stay where they are.
Also in this release
“Run refresh” works again in ConnectWise and Autotask settings.
As always, let us know if you have any feedback or requests!
Ian, Garrett & Allen
