> Do you know if Apple’s MDM is the same for their retail and corporate employees?
Apple Connect, SSO authentication service, is used by all Apple employees, both corporate and retail.
The actual MDM itself (what is allowed, how much is controlled, what can be accessed, etc. etc.) does vary from corporate to retail and between employee roles and departments and from device to device (BYOD v. Apple owned devices).
To facilitate this they use a bit of a patchwork of mainly in-house developed solutions and Jamf MDM services.
A lot of it is pretty well documented in public, The Apple Wiki page[0] on Apple’s internal apps would be a good entry point to go down the rabbit hole, should you be so inclined.
Just keep in mind that a lot of the information on the inner workings of Apple will be perpetually outdated, due to the nature of that information and its reliance on employees leaking information. You’ll find that most publicly available information is about stuff on the retail side, because corporate employees usually are more risk averse when it comes to jeopardizing their job.
0: https://theapplewiki.com/wiki/Apple_Internal_Apps