What are Managed Apple IDs?

SimpleMDM Favicon
SimpleMDM|October 28, 2019
General IT Article 2 Background
General IT Article 2 Background

Managed Apple IDs are available through Apple Business Manager (ABM) and Apple School Manager. This type of Apple ID allows you to enroll and manage devices with an MDM solution via the User Enrollment option. We’ll explain what this means for your business.

What is a Managed Apple ID?

A Managed Apple ID is owned by the business or organization, allowing for scalable administration.

Traditionally, individuals used Apple IDs designed primarily for personal use. These accounts were used for app licensing, managing iCloud accounts, accessing iCloud services, and more. Once the Apple ID was created, the original user was the only individual with access to it. This presented difficulties in a business environment.

Managed Apple IDs are the latest solution to overcoming these difficulties while providing similar functionality. The benefits include the following:

  • Simplified onboarding and troubleshooting

  • Reduced redundancy

  • ID creation at scale

  • Enhanced security

  • Improved collaboration

Users that have Apple Business Manager administrator privileges can also manage accounts. Admins can perform the following tasks:

  • Create new IDs

  • Assign roles to the IDs

  • Reset ID account passwords

  • Restrict user access to ID accounts

  • Delete IDs

  • Update account information for IDs

Additionally, Apple supports the federation of Managed Apple IDs through Microsoft Azure Active Directory and Google Workspace. That means an Apple Business Manager account can link to Microsoft Azure AD or Google Workspace. Then, ABM creates Managed Apple IDs automatically based on existing identities in the linked platform.

How to use a Managed Apple ID

Managed Apple IDs serve several purposes:

  • Grant access to the Apple Business Manager portal: Admins can delegate roles relating to what the user can and cannot access within Apple Business Manager.

  • Allow shared access: To support collaboration, users can access company accounts for Apple services, such as iCloud Drive and iCloud Notes.

  • Facilitate license assignment: Managed App licenses can be tied to a Managed Apple ID rather than the device, allowing for license transfer between devices.

  • Enable Activation Lock: Admins can lock devices if they’re lost or stolen and restore access if they’re retrieved.

  • Share devices: The Shared iPad feature allows users with separate Managed Apple IDs to log in to the same Shared iPad device. This allows for a personalized experience on a communal machine.

  • Permit User Enrollment: Designed for bring your own device (BYOD), User Enrollment allows a Managed Apple ID to be used alongside an existing Apple ID. We’ll expand on this in the next section.

Managed Apple ID users don’t have access to every Apple service. Apple Pay, Apple Music, Apple TV+, and some other features are disabled to protect the business. Users can also browse the App Store, but they cannot make purchases.

What is User Enrollment?

Apple User Enrollment is an addition to the device enrollment options supported by the Apple MDM spec starting with iOS 13 and macOS Catalina 10.15. Geared for organizations that want to support a BYOD policy, it is a significantly more privacy-focused form of enrollment. It gives the MDM only limited access to users’ devices while separating personal and corporate data.

User Enrollment requires a Managed Apple ID and must be associated with the device. The user needs to enter their Managed Apple ID credentials in order to complete the enrollment process. This ID is used to install the MDM profile, assign app licenses, provide access to shared iCloud accounts, and manage which users have access to these company-owned assets on their personal devices. A single Managed Apple ID may be used on multiple devices and does not interfere with a standard personal Apple ID configured on the device.

Managed Apple IDs provide an efficient way to secure both BYOD and company-owned Apple devices. SimpleMDM takes that convenience to the next level, enabling you to manage, secure, update, and license your fleet from a central console. Read the SimpleMDM blog to learn the ins and outs of MDM, or jump right into Apple device management with a free 30-day trial.

SimpleMDM Favicon

SimpleMDM is a mobile device management solution that helps IT teams securely update, monitor, and license Apple devices in a matter of minutes — all while staying on top of Apple updates automatically.

Related articles