The Onboarding Bottleneck: Why New Client Device Enrollment Still Eats Up Your Team’s Week
You land a new client. That’s the good news.
The bad news is what happens next: a box of new Macs and iPhones shows up, and now someone on your team has to unbox each one, log in, configure Wi-Fi and VPN, install the client’s required apps, apply security settings, and hope nothing was missed before it ships out to an end user who’s already annoyed it took this long.
Do that across a handful of new clients a month, and device enrollment quietly becomes one of the biggest time sinks in the business. It doesn’t show up on an invoice as its own line item, but it shows up everywhere else: delayed start dates, techs who could be billing elsewhere, and a first impression with a new client that starts with “sorry for the delay” instead of “you’re all set.”
Why this is harder for MSPs than it looks
Every client is a different configuration.
One client needs Okta SSO and a specific VPN profile. Another needs FileVault enforced from minute one for compliance reasons. A third has a BYOD policy that the first two don’t. Generic “enroll the device” instructions assume one environment. MSPs are running dozens of them at once, and getting the wrong Wi-Fi profile or app bundle onto the wrong client’s device isn’t just annoying, it’s a trust problem.
Manual setup doesn’t scale with growth.
Unboxing, configuring, and testing a device by hand might take twenty minutes. That’s fine for five devices. It’s the better part of two days for fifty, and it’s the reason new client rollouts get pushed onto whichever tech has a free afternoon instead of happening on a predictable schedule.
Enrollment failures are where the real time goes.
A device that doesn’t finish enrolling, drops out of management after a reset, or gets stuck mid-Setup Assistant doesn’t fail quietly. It generates a ticket, a phone call, and a tech digging through logs to figure out what happened, usually while a new employee at the client site is sitting there without a working laptop.
Slow onboarding delays time to value, and time to bill. Every day a device sits half-configured is a day the client isn’t fully live on your services and a day your team is doing setup work instead of the higher-value support that actually grows the account.
What actually fixes this
The MSPs who’ve solved this aren’t doing enrollment faster by hand. They’ve removed hands from the process entirely within their Apple device management solution, and built enough flexibility into it that “every client is different” stops being a problem:
- Zero-touch provisioning tied to Apple Business Manager, so a device configures itself the moment it’s powered on, no tech required to touch it before it reaches the end user.
- Policy assignment by client, group, role, or location, so the right Wi-Fi, VPN, apps, and compliance settings land on the right device automatically, even when you’re managing dozens of distinct client environments side by side.
- Technician access scoped per client, so the tech who supports three accounts can’t see or touch the other ninety-seven.
- Standardized templates for the basics — Wi-Fi, VPN, FileVault, compliance baselines — so a new client rollout starts from a proven configuration instead of a blank page.
- Support for company-owned and BYOD enrollment, since most MSPs are managing both, often for the same client.
- Bulk enrollment that doesn’t cap out, so a fifty-device rollout takes the same process as a five-device one.
- Real-time visibility into setup status, so you know a device is fully configured and compliant before it ships, instead of finding out it wasn’t when the client calls.
- Built-in remediation for the devices that don’t enroll cleanly — re-enrollment tools, alerts when a device drops out of management, and a way to fix it without a truck roll or an hour on the phone.
Watch the discussion in our sudotalks series with Selina Ali and Daniel Allen for more detail.
What manual onboarding actually costs you, mapped against automation
| Manual onboarding | Zero-touch onboarding | |
|---|---|---|
| Tech involvement per device | Unboxing, login, and configuration by hand | Device configures itself on first boot, no tech touch required |
| Consistency across clients | Depends on which tech did the setup, and whether they remembered every step | Policies and templates apply automatically, the same way every time |
| Scaling from 5 to 50 devices | Time cost scales roughly linearly with device count | Bulk enrollment handles unlimited devices through the same workflow |
| Failed or stuck enrollments | Found when the end user calls, then diagnosed from scratch | Flagged in real time, with built-in remediation tools to fix them |
| New client rollout timeline | Whenever a tech has a free afternoon | Predictable, repeatable, schedulable |
| End-user experience | Inconsistent, sometimes a bare login screen with no context | Branded, guided setup with real-time progress the user can actually see |
What onboarding automation actually looks like once it’s built
It’s worth being specific here, because “automate onboarding” can mean a lot of different things depending on the platform. In Addigy, it plays out like this:
Automated Device Enrollment (ADE) provisions Apple devices automatically through Apple Business Manager, alongside manual, user-initiated, and BYOD enrollment options for the devices that don’t fit the zero-touch path. Devices are enrolled and configured during Setup Assistant itself: end users log in with SSO through Google, Okta, Azure, or SAML, and apps, settings, and compliance tools are already in place by the time they reach the desktop.
Policies and smart groups tie into Apple Business Manager, Active Directory, or your identity provider, so the correct configuration — Wi-Fi, VPN, FileVault, app bundle — gets applied automatically based on the client, department, or role, rather than a tech manually picking the right profile for the right device. Addigy’s hierarchical policy structure means you can set a configuration once at the parent level and have it cascade down to every organization or tenant, while still layering in client-specific automations where you need them. Bulk enrollment covers unlimited macOS, iOS, and iPadOS devices, whether you’re onboarding one new hire or an entire new client fleet.
Addigy Assist takes over from there for the actual setup experience on Macs. It’s a macOS-native app that runs after enrollment, showing the end user real-time progress as apps and policies install instead of a blank screen and a lot of waiting. Configuring it takes under 10 minutes in the Addigy console, with no custom scripting required. Smart Prompts handle the interruptions that normally turn into tickets — low battery, a dropped Wi-Fi connection, a required restart — by guiding the user through resolving them on their own. Addigy LANCache speeds up larger app deployments by avoiding redundant downloads across devices on the same network.
Prebuilt Apps deploy your client’s entire app catalog silently in the background during setup, with PPPC permissions and system extensions preconfigured so users aren’t hit with a string of approval pop-ups on day one. And because you’re doing this across multiple clients, Addigy lets you brand the onboarding experience per client, logos and messaging included, so a new employee’s first impression is of their employer, not a generic MDM screen.
When something doesn’t go as planned, real-time visibility into setup status means you catch a stuck or failed enrollment before it ships rather than when the client calls. Re-enrollment scripts, QR codes, and GoLive rescans get a dropped-out device back under control without pulling a tech off other work or scheduling a truck roll.
A few things MSPs commonly ask before switching
Does this work for migrations, not just new devices? Yes. Moving an existing fleet off another MDM doesn’t require wiping every machine — migration is a guided process with a dedicated Solutions Architect, a trial run on test devices, and a scheduled migration day, so end users see minimal disruption. Worth knowing up front: a Mac migrated in place enrolls through user-approved enrollment rather than ADE. If you want a device to carry full ADE status and Setup Assistant–time configuration, it needs to be assigned to Addigy in Apple Business Manager and run through Setup Assistant. Most fleets move as a mix of both, and that’s the conversation to have during the strategy review.
Can we restrict which techs see or touch which clients? Yes. Policy restrictions and user roles limit technician visibility and actions per client or tenant, which matters both for security and for keeping clients confident their environment isn’t being touched by someone unfamiliar with it.
Does this replace our documentation, or do we still need client-specific runbooks? Standardized templates cover the baseline (Wi-Fi, VPN, FileVault, compliance settings), but you still layer client-specific policies on top. The difference is that the baseline is enforced automatically instead of living in a document a tech has to remember to follow.
The takeaway for MSPs
Device enrollment is one of the few parts of the client relationship that happens before you’ve had a chance to prove your value, and it’s often the first real impression a new client, or a new employee at an existing client, gets of how you operate. Doing it by hand doesn’t just cost your team hours, it puts that first impression at risk every single time a new client comes on board, and it caps how fast you can grow without growing headcount alongside it. Valiant Technology, an MSP that consolidated its Apple device workflows onto Addigy, grew top-line revenue 33% over three years and moved EBITDA from 2% to 10% while scaling from roughly 1,500 endpoints to more than 3,500.
If new client onboarding is still eating up a predictable chunk of your team’s week, start a free trial and run your next rollout through it — or see how Addigy Assist works first.
