Alma
Evans

How to easily create Managed Apple ID using Azure AD?

Alma Evans

Nov 12, 2020

10 min read

How to easily create Managed Apple ID using Azure AD

In an organization, when you have tens of thousands of Apple devices for work, relying on Apple Business Manager and Managed Apple ID for business is an easy way to integrate, deploy, manage, and secure your endpoints from a central management point. Apple’s latest innovations have already broadened the usability of Managed Apple ID with Apple Business Manager specifically to increase the value of Apple use in a business setting.

Use Hexnode with ABM and empower your workforce with Apple devices
There are certain times when Managed Apple ID may be too restrictive to use, but in most cases, they can be a perfect fit for businesses of all sizes. Knowing how to create Managed Apple IDs and deal with them is really important to make an informed decision while opting between Managed Apple IDs and standard Apple IDs. This guide aims to provide you with enough information to create Managed Apple IDs in a simple way possible using Microsoft Azure Active Directory.

What are Managed Apple IDs?

Managed Apple IDs are accounts created on behalf of employees/students by organizations/schools through Apple Business Manager and Apple School Manager. They serve the same purpose of saving user settings that can be recognized by Apple devices, tools, and services to prove the owner’s authenticity just as the normal Apple IDs do.

Managed Apple IDs have been around Apple School Manager for several years, but the feature came to Apple Business Manager only recently. Managed Apple IDs are designed to fulfill specific organizational needs and role-based administration of corporate assets.

IT administrators can centrally manage Managed Apple IDs by:

  • Creating accounts in bulk
  • Deleting unused accounts
  • Resetting passwords
  • Restricting account access
  • Updating account information
  • Assigning administrative roles

Why do businesses use Managed Apple IDs?

Administrators primarily use Managed Apple IDs to access the ABM or ASM portals. Users also leverage these IDs to collaborate and access essential business apps and services, including iCloud Drive, iTunes, Notes, Apple Music, and iWork.

Additionally, organizations use Managed Apple IDs to manage app licensing, personalize devices, administer iCloud accounts, and share enterprise access for teamwork.

Managed Apple IDs are also a vital part of the User enrollment of iOS, iPadOS, and macOS devices. In such cases, they can be used alongside the standard personal Apple IDs.

As they are devised for enterprise use, to ensure enterprise security Managed Apple IDs automatically disables several features, including:

  • Apple Pay
  • iCloud Mail
  • iCloud Family Sharing
  • iCloud Keychain
  • App Store purchasing
  • iTunes purchasing
  • Media services like Apple Music, Apple Radio, Apple Fitness+, Apple One, Apple Arcade, Apple News+, and Apple TV+
  • Find My services
  • Adding HomeKit devices to the Home app
  • FaceTime
  • iMessage

Standard Apple ID vs. Managed Apple ID

Both Standard Apple IDs and Managed Apple IDs are created to personalize devices, but the difference is that the latter is made for personal use while the former is intended for company-owned devices designed to meet organizational needs.

Apple IDs are created by individual users, and once made, they are only used and accessed by the original creator. In contrast to this, Managed Apple IDs are created, managed, and accessed whenever needed by the user’s organization.

In a business environment, there are many perks of opting for Managed Apple IDs over Standard Apple IDs as individual IDs are difficult to use on a large scale. With Managed Apple IDs, the responsibility for the entire IDs is shifted from the employees to the enterprise IT so that the employees no longer have to worry about installing software and tools onto the work devices by themselves.

Unlike standard Apple IDs, even if an employee leaves the organization, there is no risk of being unable to access the device as the enterprise IT has full knowledge of everything regarding Managed Apple IDs. In addition, Managed Apple IDs heighten security because administrators can thoroughly validate everything before pushing it to the devices.

How are Managed Apple IDs created?

Gone are the days where users must manually create their own Apple IDs and use the same for business related needs. Managed Apple IDs can be created by the user’s IT team, either manually or automatically:

  • Directly from Apple Business Manager
  • Using federated authentication with Azure AD
  • Using SCIM with Azure AD

Apple recommended format for Managed Apple IDs to avoid confusion

The recommended structure for Managed Apple ID consists of 3 parts:

  • The username followed by @ sign
  • The text “appleid” followed by a period
  • The domain name for your business

 

username@appleid.domain.com


Though the commonly used method is to manually create Managed Apple IDs using the Apple Business Manager portal, there are other ways to simplify Managed Apple ID creation using Microsoft Azure AD.

Creating Managed Apple ID in Apple Business Manager

In Apple Business Manager, admins can manually create unique Managed Apple IDs for each user accounts using already verified domain names following the below steps:

  • Sign in to Apple Business Manager using an Administrator or People Manager account.
  • Go to Accounts and search for the required account.
  • Select the user and click Edit in the Account row.
  • Click the Add button and choose how the Managed Apple ID should look like.
  • Choose a verified domain name from the list and click Continue.
  • Wait until the activity is completed or click Close.
  • Click Done once finished.

Creating Managed Apple IDs manually at scale can be difficult for businesses at times, but so long as they have Azure Active Directory, that’s no longer going to be an issue. Managed Apple IDs can be created through integration with third-party identity providers like Azure AD.

Creating Managed Apple ID using Azure AD

Apple Business Manager allows organizations to integrate with Microsoft Azure Active Directory to simplify Managed Apple ID creation.

Instead of manually creating accounts, IT administrators can automatically provision Managed Apple IDs using their existing Azure AD environment. You can easily complete the straightforward setup process using a domain administrator account.

Managed Apple IDs use the same credentials as Azure AD users. Organizations can choose between two provisioning methods:

  • Just-in-Time (JIT) account creation with federated authentication
  • System for Cross-domain Identity Management (SCIM)

Using federated authentication to create Managed Apple ID

Federated authentication provides an easy way to sync the identity management solution with ABM to create Managed Apple IDs. Federated authentication links an instance of Azure AD with ABM to allow users to leverage their existing Azure AD username and passwords as their Managed Apple IDs. Users can sign into a set of Apple services and shared devices using their Azure AD credentials.

Benefits

Creating Managed Apple IDs using federated authentication with Azure AD offers many benefits that may seem less obvious. At its core, this method is able to address most of the challenges regarding automated provisioning, single sign-on, and security.

  • They provide a great way to create a seamless login experience, streamlined setup, and flexible device enrollment for the users.
  • Organizations avoid spending time creating accounts in advance. Instead, the system automatically creates Managed Apple IDs when users sign into their devices or access Apple services.
  • It provides a single sign on experience for their Apple or Microsoft corporate identity as employees can use their existing Azure AD credentials, and there is no need to juggle with multiple passwords.
  • Users get a personalized experience even if they are using a shared device.
  • The device management process is also simplified as Managed Apple IDs enable constant communication between ABM and Azure AD. When the organization deactivates an employee’s Azure AD account, the Managed Apple ID turns off as well.
Requirements

Organizations should meet the following criteria to use federated authentication with ABM:

  • Should have an on-premises Active Directory.
  • Should have Apple devices running iOS 11.3 or later, iPadOS 13.1 or later, and macOS 10.13.4 or later.
  • Domain shouldn’t be used by any other organization.
  • User Principal Name of the users should match their email addresses.
Procedure
  • Sign in to Apple Business Manager using an Administrator or People Manager account. Add the domains to be federated.
  • Grand permission for ABM to read user profiles by signing in to Azure AD using a Global administrator or Application administrator account.
  • To verify domain ownership, sign in to Azure AD within ABM using an account from the domain you want to federate.
  • ABM checks whether there are any potential conflicts due to any existing Apple IDs with the same domain set up by any other organization. If Apple discovers another organization using Apple IDs with the same domain, Apple will investigate to determine the rightful owner. If both the organizations are valid to claim the domain, none of them can use it to federate.
  • If ABM finds any other consumer IDs, it notifies those users to change their associated email addresses.
  • Businesses can migrate existing Managed Apple IDs by changing their associated domain, username, and other details.

Azure AD acts as the identity provider when businesses are using federated authentication. To transfer information like login credentials and connect Azure AD with ABM for the Managed Apple ID creation process, federated authentication uses Security Assertion Markup Language (SAML).

Once you complete the integration, the system automatically creates Managed Apple IDs when Azure AD users log into any Apple service. This process is termed as Just in time (JIT) account creation. If any of the employees already have Apple IDs related to their work emails, an automatic conflict resolution process starts running after a specified period of time.

After the integration process, Apple notifies all consumer Apple IDs using the company domain to change their IDs within 60 days. Following this period, the system automatically initiates the conflict resolution process.

Using SCIM instead of JIT with federated authentication to create Managed Apple ID

System for Cross-domain Identity Management (SCIM) is a feature that allows importing users to Apple Business Manager. SCIM allows merging ABM properties with accounts imported from Azure AD. Only users with Application Administrator, Cloud Application Administrator, Application Owner, or Global Administrator privileges can configure SCIM.

When sending federated Azure AD accounts to ABM, Azure AD acts as the identity provider for user authentication. Organizations can also create Managed Apple IDs for all of these federated Azure AD accounts. This is done by using the SCIM “Sync all users and groups” provisioning option.

SCIM provides additional lifecycle automation compared to JIT:

  • Automatically provisions new user accounts.
  • Automatically deprovisions accounts when users leave the organization.
  • Synchronizes user lifecycle changes from Azure AD.
  • Reduces manual account management.
Share

Alma Evans

Product Marketing @ Hexnode. Exploring the digital frontier, one line of wonder at a time...