In an organization, when you have tens of thousands of Apple devices for work, relying on Apple Business Manager and Managed Apple ID for business is an easy way to integrate, deploy, manage, and secure your endpoints from a central management point. Apple’s latest innovations have already broadened the usability of Managed Apple ID with Apple Business Manager specifically to increase the value of Apple use in a business setting.
What are Managed Apple IDs?
Managed Apple IDs are accounts created on behalf of employees/students by organizations/schools through Apple Business Manager and Apple School Manager. They serve the same purpose of saving user settings that can be recognized by Apple devices, tools, and services to prove the owner’s authenticity just as the normal Apple IDs do.
Managed Apple IDs have been around Apple School Manager for several years, but the feature came to Apple Business Manager only recently. Managed Apple IDs are designed to fulfill specific organizational needs and role-based administration of corporate assets.
IT administrators can centrally manage Managed Apple IDs by:
- Creating accounts in bulk
- Deleting unused accounts
- Resetting passwords
- Restricting account access
- Updating account information
- Assigning administrative roles
Why do businesses use Managed Apple IDs?
Administrators primarily use Managed Apple IDs to access the ABM or ASM portals. Users also leverage these IDs to collaborate and access essential business apps and services, including iCloud Drive, iTunes, Notes, Apple Music, and iWork.
Additionally, organizations use Managed Apple IDs to manage app licensing, personalize devices, administer iCloud accounts, and share enterprise access for teamwork.
Managed Apple IDs are also a vital part of the User enrollment of iOS, iPadOS, and macOS devices. In such cases, they can be used alongside the standard personal Apple IDs.
As they are devised for enterprise use, to ensure enterprise security Managed Apple IDs automatically disables several features, including:
- Apple Pay
- iCloud Mail
- iCloud Family Sharing
- iCloud Keychain
- App Store purchasing
- iTunes purchasing
- Media services like Apple Music, Apple Radio, Apple Fitness+, Apple One, Apple Arcade, Apple News+, and Apple TV+
- Find My services
- Adding HomeKit devices to the Home app
- FaceTime
- iMessage
How are Managed Apple IDs created?
Gone are the days where users must manually create their own Apple IDs and use the same for business related needs. Managed Apple IDs can be created by the user’s IT team, either manually or automatically:
- Directly from Apple Business Manager
- Using federated authentication with Azure AD
- Using SCIM with Azure AD
Though the commonly used method is to manually create Managed Apple IDs using the Apple Business Manager portal, there are other ways to simplify Managed Apple ID creation using Microsoft Azure AD.
Creating Managed Apple ID in Apple Business Manager
In Apple Business Manager, admins can manually create unique Managed Apple IDs for each user accounts using already verified domain names following the below steps:
- Sign in to Apple Business Manager using an Administrator or People Manager account.
- Go to Accounts and search for the required account.
- Select the user and click Edit in the Account row.
- Click the Add button and choose how the Managed Apple ID should look like.
- Choose a verified domain name from the list and click Continue.
- Wait until the activity is completed or click Close.
- Click Done once finished.
Creating Managed Apple IDs manually at scale can be difficult for businesses at times, but so long as they have Azure Active Directory, that’s no longer going to be an issue. Managed Apple IDs can be created through integration with third-party identity providers like Azure AD.
Creating Managed Apple ID using Azure AD
Apple Business Manager allows organizations to integrate with Microsoft Azure Active Directory to simplify Managed Apple ID creation.
Instead of manually creating accounts, IT administrators can automatically provision Managed Apple IDs using their existing Azure AD environment. You can easily complete the straightforward setup process using a domain administrator account.
Managed Apple IDs use the same credentials as Azure AD users. Organizations can choose between two provisioning methods:
- Just-in-Time (JIT) account creation with federated authentication
- System for Cross-domain Identity Management (SCIM)
Using federated authentication to create Managed Apple ID
Federated authentication provides an easy way to sync the identity management solution with ABM to create Managed Apple IDs. Federated authentication links an instance of Azure AD with ABM to allow users to leverage their existing Azure AD username and passwords as their Managed Apple IDs. Users can sign into a set of Apple services and shared devices using their Azure AD credentials.
Benefits
Creating Managed Apple IDs using federated authentication with Azure AD offers many benefits that may seem less obvious. At its core, this method is able to address most of the challenges regarding automated provisioning, single sign-on, and security.
- They provide a great way to create a seamless login experience, streamlined setup, and flexible device enrollment for the users.
- Organizations avoid spending time creating accounts in advance. Instead, the system automatically creates Managed Apple IDs when users sign into their devices or access Apple services.
- It provides a single sign on experience for their Apple or Microsoft corporate identity as employees can use their existing Azure AD credentials, and there is no need to juggle with multiple passwords.
- Users get a personalized experience even if they are using a shared device.
- The device management process is also simplified as Managed Apple IDs enable constant communication between ABM and Azure AD. When the organization deactivates an employee’s Azure AD account, the Managed Apple ID turns off as well.
Requirements
Organizations should meet the following criteria to use federated authentication with ABM:
- Should have an on-premises Active Directory.
- Should have Apple devices running iOS 11.3 or later, iPadOS 13.1 or later, and macOS 10.13.4 or later.
- Domain shouldn’t be used by any other organization.
- User Principal Name of the users should match their email addresses.
Procedure
- Sign in to Apple Business Manager using an Administrator or People Manager account. Add the domains to be federated.
- Grand permission for ABM to read user profiles by signing in to Azure AD using a Global administrator or Application administrator account.
- To verify domain ownership, sign in to Azure AD within ABM using an account from the domain you want to federate.
- ABM checks whether there are any potential conflicts due to any existing Apple IDs with the same domain set up by any other organization. If Apple discovers another organization using Apple IDs with the same domain, Apple will investigate to determine the rightful owner. If both the organizations are valid to claim the domain, none of them can use it to federate.
- If ABM finds any other consumer IDs, it notifies those users to change their associated email addresses.
- Businesses can migrate existing Managed Apple IDs by changing their associated domain, username, and other details.
Azure AD acts as the identity provider when businesses are using federated authentication. To transfer information like login credentials and connect Azure AD with ABM for the Managed Apple ID creation process, federated authentication uses Security Assertion Markup Language (SAML).
Once you complete the integration, the system automatically creates Managed Apple IDs when Azure AD users log into any Apple service. This process is termed as Just in time (JIT) account creation. If any of the employees already have Apple IDs related to their work emails, an automatic conflict resolution process starts running after a specified period of time.
After the integration process, Apple notifies all consumer Apple IDs using the company domain to change their IDs within 60 days. Following this period, the system automatically initiates the conflict resolution process.
Using SCIM instead of JIT with federated authentication to create Managed Apple ID
System for Cross-domain Identity Management (SCIM) is a feature that allows importing users to Apple Business Manager. SCIM allows merging ABM properties with accounts imported from Azure AD. Only users with Application Administrator, Cloud Application Administrator, Application Owner, or Global Administrator privileges can configure SCIM.
When sending federated Azure AD accounts to ABM, Azure AD acts as the identity provider for user authentication. Organizations can also create Managed Apple IDs for all of these federated Azure AD accounts. This is done by using the SCIM “Sync all users and groups” provisioning option.
SCIM provides additional lifecycle automation compared to JIT:
- Automatically provisions new user accounts.
- Automatically deprovisions accounts when users leave the organization.
- Synchronizes user lifecycle changes from Azure AD.
- Reduces manual account management.