Why Windows Experts Struggle with Mac Management, and What That Costs Your Business

Why Windows Experts Struggle with Mac Management, and What That Costs Your Business

This post is NOT an attack on Windows expertise. Windows administration is a deep, complex discipline. The skills required to manage Active Directory, Group Policy, Intune, Exchange and the rest of the Microsoft stack at scale take years to develop and are genuinely valuable.

The problem is not that Windows IT professionals lack skill. The problem is that those skills do not transfer to Mac management in the way most people assume. And in a world where UK businesses increasingly run mixed Apple and Windows fleets, that assumption is costing businesses real money, in security gaps, compliance failures, user frustration and wasted IT time.

This post explains why. Not to embarrass anyone, but because understanding the gap is the only way to close it.

The assumption that creates the problem

When a business adds Macs to a Windows-majority fleet, the most common decision is to hand Mac management to the existing IT team or IT provider. The logic is straightforward: they already manage all the devices, they understand the network, they have the admin access. Adding some Macs to their workload seems like a small extension of what they already do.

What actually happens is that the IT team applies Windows thinking to a platform that works fundamentally differently. Not slightly differently. Fundamentally differently. The management model, the security architecture, the update mechanism, the application framework, the identity integration, all of it works differently on Mac.

The result is a fleet of Macs that appear to be managed but are not managed well. Policies that do not apply correctly. Patches that do not deploy reliably. Security configurations that look right on paper but have gaps in practice. Users end up with a worse experience on Mac than they would on Windows, not because Mac is worse, but because nobody who understands the platform configured it.

The Group Policy problem

Group Policy is the foundation of Windows device management. It is how Windows IT teams push settings, enforce policies, restrict software and configure security across every device in the domain. If you have spent years managing Windows, Group Policy is the mental model through which you understand device management.

Mac does not have Group Policy. It has never had Group Policy. It will never have Group Policy (hopefully). Mac uses configuration profiles, XML files that define settings and reach devices through an MDM platform.They achieve some of the same outcomes as Group Policy but through a completely different mechanism with completely different logic, completely different syntax and completely different limitations.

A Windows IT professional who knows Group Policy inside out does not automatically know configuration profiles. They are different things. A preference key in a macOS configuration profile is not a registry entry. An MDM scope in a MDM is not an OU in Active Directory. A PreStage enrolment in MDM is not an Autopilot deployment profile. The concepts map loosely but the implementation differs in ways that matter enormously in practice.

The common mistake: a Windows admin inherits a Mac fleet and tries to replicate the Group Policy logic they know in the MDM platform. They create policies that make sense from a Windows perspective but either fail to apply correctly on macOS, hit the wrong scope or conflict with how macOS handles configuration delivery. The devices appear enrolled. The policies appear applied. Under the hood, the configuration is wrong.

Active Directory thinking does not translate

Most Windows environments centre on Active Directory. Users, computers, groups and policies all live in AD. The domain is the boundary. Everything flows from the directory.

Mac does not join Active Directory the way Windows does. You can bind a Mac to Active Directory and Apple supports it, but it is increasingly the wrong approach for modern Mac management and creates more problems than it solves.

Group Policy requires Active Directory, an on-premises directory service. MDM and Group Policy serve different functions and neither replaces the other entirely. This is obvious to anyone who manages both platforms. It is not obvious to a Windows administrator encountering Mac management for the first time.

Modern Mac management uses Apple Business as the device enrolment layer, an MDM platform like Jamf Pro/Iru for policy delivery, and a cloud identity provider like Okta, Microsoft Entra ID or Google Workspace, as the identity layer. The directory is not on-premises. The policies are not delivered through AD. The user accounts are not domain accounts in the traditional sense.

A Windows administrator who joins a Mac to Active Directory, creates a corresponding computer object and tries to apply Group Policy to it is not managing the Mac incorrectly out of malice. They are applying the only mental model they have to a platform where that model does not fit. The Mac will appear domain-joined. Logins may appear to work. Under the surface, the security configuration that MDM should be enforcing is absent, because the Mac was never properly enrolled in an MDM platform.

The antivirus assumption

Windows has had a persistent malware problem for decades. As a result, Windows IT management culture places significant emphasis on antivirus software. Installing, managing and monitoring antivirus across the Windows fleet is a standard, expected part of the Windows IT workflow.

When a Windows IT team inherits a Mac fleet, the antivirus mindset comes with them. They install a Windows-oriented endpoint protection product on the Macs, confirm it is running and consider the malware question answered.

The Mac security model works differently. Apple’s built-in security architecture, XProtect, Gatekeeper, System Integrity Protection, the notarisation requirement, the app sandbox and creates a fundamentally different threat landscape than Windows. These controls are deeply embedded in the operating system and interact with management tools in specific ways.

A Windows-oriented endpoint protection tool that works excellently on Windows may create conflicts, performance issues or management blind spots on Mac. The right endpoint protection tools for Mac like Jamf Protect, CrowdStrike Falcon and few others with Mac support, (example: Microsoft Defender for Business with proper Mac configuration) are chosen and configured with the Mac security model in mind, not ported from a Windows deployment.

This matters for Cyber compliance specifically. An assessor reviewing your malware protection posture for an Apple fleet expects to see Mac-native or Mac-appropriate tools properly configured. A Windows endpoint protection tool installed on Macs without proper Mac-specific configuration is not the same as a well-implemented Mac security posture, regardless of what the dashboard shows.

The patching gap

Windows patching is largely centralised through Windows Update, WSUS or Intune’s Windows Update for Business integration. Windows IT teams develop strong instincts around patch management for Windows, the Patch Tuesday cycle, the testing rings, the deployment groups.

Mac patching works differently and the differences create gaps when managed by Windows-trained teams.

macOS updates come from Apple’s servers and are managed through MDM policy enforcement. iOS and iPadOS updates for iPhones and iPads in scope follow the same mechanism. Third-party application updates on Mac like Chrome, Slack, Zoom, Adobe and dozens of others, do not go through Windows Update or any equivalent central Windows patching mechanism. Each application has its own update mechanism.

A Windows IT team managing a Mac fleet with Intune faces a specific and significant problem here. Intune natively patches only a limited number of Microsoft applications on Mac. Third-party application patching on Mac via Intune requires custom scripts, manual packaging or additional tooling.

A Windows admin comfortable with Patch My PC integrating with Intune for Windows application patching will find that the same tool does not deliver the same breadth of coverage on Mac. The Jamf App Catalog covers over 190 Mac applications with automated patching. There is no equivalent native solution in Intune for Mac.

The practical consequence for businesses relying on Windows-trained IT teams to manage their Mac fleet: Windows devices are patched comprehensively within the Cyber Essentials 14-day window. Mac third-party applications are patched inconsistently, manually or not at all, because the tooling the IT team knows does not work the same way on Mac.

The enrolment assumption

Windows device management starts with domain join or Entra ID join. The enrolment model is familiar to any Windows IT administrator.

Mac enrolment through Apple Business and MDM PreStage is a different process that trips up Windows-trained teams consistently.

The most common mistake: a Windows IT team receives new Macs and enrolls them manually, connecting to the company Wi-Fi, downloading a management profile from a URL, clicking through the enrolment flow. The Macs appear enrolled. The MDM platform shows them as managed. What actually happened is user-initiated enrolment rather than Automated Device Enrolment through Apple Business.

The difference is significant. User-initiated enrolment creates an enrolment that the user can remove. ADE enrolment through Apple Business creates a supervised, persistent enrolment that the user cannot remove. Supervision enables a significantly broader set of management capabilities, restrictions, configuration options and security controls that are simply unavailable on non-supervised devices.

A Mac fleet enrolled manually by a Windows IT team is a fleet where users can unenrol their own devices, where supervision is absent and where a significant proportion of the management capability of the MDM platform is simply unavailable. The fleet looks managed. It is not managed well.

The FileVault misunderstanding

FileVault is macOS’s full disk encryption. It is the Mac equivalent of BitLocker on Windows. Both encrypt the disk. The management model and the recovery key architecture are completely different.

Windows IT teams managing BitLocker understand the escrowing of recovery keys to Active Directory or Entra ID. They are comfortable with the BitLocker management workflow in Intune or Group Policy.

FileVault management through MDM works differently. The recovery key must be escrowed to the MDM platform at the point of FileVault enablement. If FileVault is enabled by the user before MDM enrolment or if the enrolment sequence is incorrect then the recovery key may not escrow to the MDM platform. The disk is encrypted. The IT team has no recovery key. When the user forgets their password or the device needs to be recovered, IT has no way to unlock the device.

This is a scenario that plays out repeatedly in Mac fleets managed by Windows-oriented IT teams. BitLocker key escrowing is handled differently by Windows, and the assumption that FileVault works the same way leads to Mac fleets where encryption is technically enabled but the recovery keys are not centrally held.

The user experience consequence

Beyond the security and compliance gaps, there is a practical user experience consequence that businesses often underestimate.

Mac users chose Mac for a reason. They are typically more technically capable than average, more opinionated about their tools and more sensitive to a poorly configured environment. A developer whose Mac has been configured by a Windows IT team using Windows logic will notice. The policies will feel wrong. The restrictions will be in the wrong places. The management tools may conflict with the development workflow.

The result is shadow IT. Developers find workarounds. Settings get changed. MDM profiles get removed where possible. The carefully configured management environment degrades as users work around it.

This is not a user behaviour problem. It is an IT configuration problem. A well-configured Mac environment, built by someone who understands how Mac users work and what Mac management is designed to do, does not generate the same friction. Users stay inside the managed environment because the managed environment does not get in their way.

What this means for Cyber Essentials compliance

All of the gaps above, misconfigured policies, absent supervision, inconsistent patching, incorrect FileVault management have a direct bearing on Cyber Essentials compliance.

A business that achieves Cyber Essentials certification with a Windows-trained IT team managing their Mac fleet may have attested to controls that are not correctly implemented. The self-assessment questionnaire asks whether controls are in place. A Windows IT team that believes they have correctly implemented Mac management will answer yes. An independent technical assessor conducting a Cyber Essentials Plus audit will find the gaps.

This is one of the most common patterns we see when businesses come to nDuo after having their Mac fleet managed by a generalist or Windows-oriented IT provider. The paperwork says the controls are in place. The technical reality does not match the paperwork.

The honest point about Windows expertise

None of the above is a criticism of Windows expertise. A skilled Windows administrator is genuinely valuable and the skills involved in managing a complex Windows environment at scale are not trivial.

The point is specificity. Mac management requires Mac expertise in the same way that Windows management requires Windows expertise. A Mac specialist handed a complex Active Directory environment would make the same kinds of mistakes in reverse, applying Mac thinking to a platform where it does not fit.

The businesses that manage mixed fleets well understand this. They do not ask their Windows IT team to manage Macs without Mac-specific support. They either develop Apple expertise in-house or they work with a specialist partner for the Apple part of the fleet while keeping Windows management with their existing team.

The worst outcome and the most common is a Windows-oriented IT provider who manages the Mac fleet as an afterthought, uses the tools they know rather than the tools the platform requires, and produces a fleet that appears managed but has significant gaps underneath.

How to tell if your Mac fleet has this problem

Ask your current IT provider these questions:

1. Are your Macs enrolled through Apple Business Manager with Automated Device Enrolment or through manual user-initiated enrolment? If they cannot answer immediately, that is a signal.

2. Are your Macs supervised? Supervision is only available through ADE. If they are not sure, the answer is probably no.

3. Are your FileVault recovery keys escrowed to your MDM platform? Ask them to show you the recovery key for a specific device. If they cannot, the keys are not held centrally.

4. Which MDM platform manages your Macs and how do third-party applications like Chrome, Slack, Zoom get patched on Mac? If the answer involves Windows tools or manual processes, there is a gap.

5. What compliance reports does your MDM generate for Cyber Essentials? If they cannot produce a device-by-device patch compliance report and encryption status report, the compliance evidence trail does not exist.

These are not trick questions. A team with genuine Mac expertise will answer all of them immediately and specifically. A team managing Mac as an afterthought will struggle.

Getting Mac management right

The fix is not necessarily replacing your existing IT provider. For many businesses, the right answer is a specialist Apple partner working alongside the existing Windows IT team, handling the Apple-specific management while the existing team continues to do what they do well.

This is exactly how we work with many nDuo clients. The Windows IT function stays with the team that knows it. The Apple MDM implementation, the Jamf Pro configuration, the Cyber Essentials compliance posture for the Apple fleet and the managed IT support for Mac users comes to us.

The two teams integrate through shared tooling – nDuo iQ brings Jamf Pro and Microsoft Intune into a single management view so both teams can see the full fleet without operating in separate silos.

If you are an IT Director who has read this post and recognised some of these patterns in your current environment, or a business owner who has noticed that your Mac users seem to have a worse experience than your Windows users despite having the same IT provider, the starting point is a conversation.

Read our Apple IT support page for more on how we work with UK businesses, or our Jamf Pro vs Microsoft Intune comparison to understand the platform differences in more detail.

Book a free consultation with our team and we will give you an honest assessment of your current Mac management posture.