Block iCloud or Apple ID sign-in on iPads managed with HexnodeSolved

Participant
Discussion
2 days ago Jun 01, 2026

I’m setting up a group of iPads in Hexnode and want them to be managed without any personal Apple ID or iCloud account. In the iOS policy, I disabled the option to modify accounts under Advanced Restrictions, but users can still open Settings and sign in with an Apple ID. I also want to install apps without asking users to sign in to the App Store. Is VPP enough for that, or is there another setting needed to fully block Apple ID sign-in?

Replies (5)

Marked SolutionPending Review
Hexnode Expert
2 days ago Jun 01, 2026
Marked SolutionPending Review

For app installation without requiring an Apple Account on the device, you can use Apple Business with Apps and Books, commonly referred to as VPP. Once the app licenses are acquired in Apple Business and the VPP token is configured and synced in Hexnode, apps can be deployed remotely from Hexnode without requiring users to sign in to the App Store.

For blocking Apple Account or iCloud sign-in, the relevant restriction is to prevent account modification. In Hexnode, this is configured through the iOS Advanced restrictions policy by disabling ‘Modify an account’. However, Apple requires the iPad to be supervised for this restriction to take effect.

If the iPad is not supervised, users may still be able to add an Apple Account even if the restriction is configured in the policy.

Marked SolutionPending Review
Participant
2 days ago Jun 01, 2026
Marked SolutionPending Review

That explains part of it. I synced the app licenses from Apple Business and the Hexnode app installed successfully after that. But the iPads still allow Apple ID sign-in. These devices are not currently listed in Apple Business. Does that mean the restriction will not work at all?

Marked SolutionPending Review
Hexnode Expert
2 days ago Jun 01, 2026
Marked SolutionPending Review

Correct. Restrictions such as blocking Apple ID/iCloud sign-in by preventing account modification require the device to be supervised.

You can enable supervision in one of these ways:

  1. Apple Business with Automated Device Enrollment: If the iPads can be added to Apple Business Manager, they can be enrolled through ADE and supervised automatically during setup.
  2. Apple Configurator: If the devices cannot be added to Apple Business, they can be manually supervised using Apple Configurator on a Mac. This requires physically connecting the devices and typically involves erasing/factory resetting them during the supervision process.After the iPads are supervised and enrolled in Hexnode, the account modification restriction can be enforced, and users will be prevented from adding Apple ID/iCloud accounts.
Marked SolutionPending Review
Participant
2 days ago Jun 01, 2026
Marked SolutionPending Review

Is there any workaround using a configuration profile from another tool, like creating a custom profile and pushing it to the iPad?

Marked SolutionPending Review
Hexnode Expert
2 days ago Jun 01, 2026
Marked SolutionPending Review

No reliable workaround is available for unsupervised iPads.

This is an Apple enforcement requirement, not a Hexnode-specific limitation. A configuration profile can include the account modification restriction, but iOS will only enforce that restriction on supervised devices. To block Apple Account sign-in and keep the iPads managed without personal Apple accounts, the devices must first be supervised through Apple Business or Apple Configurator. Once supervised, you can combine the account modification restriction with VPP-based app deployment so apps install silently without requiring an Apple Account on the device.

Save