Skip to main content

Glossary

Managed Apple ID

A Managed Apple ID is a work account that your organization creates and owns in Apple Business Manager or Apple School Manager, instead of an account the employee signs up for with Apple directly. It carries the Apple services a company needs (device enrollment, Shared iPad, managed iCloud storage, Sign in with Apple at Work) while the admin keeps the ability to reset the password, audit the account and take it back when the person leaves.

How it works

You verify a domain you control in Apple Business Manager, then create accounts on it. The simplest way is federated authentication: link ABM to Microsoft Entra ID (supported since 2021) or Google Workspace (added in 2023) and Apple stops owning the password entirely. The user types their work email on the iPhone, gets redirected to the identity provider, passes MFA there, and comes back with a Managed Apple ID. No separate credential to distribute, no help desk ticket when the password rotates.

A Managed Apple ID is deliberately narrower than the personal Apple Account Apple renamed in 2024. It can use iCloud Drive, Notes, Reminders, Pages, Numbers and Keynote, with 50 GB of managed storage granted through ABM, and it can sign in to Shared iPad and to User Enrollment. It cannot buy anything: no App Store purchases, no in-app purchases, no Apple Pay, no Apple Card, no paid iCloud upgrade. Apple also keeps it out of the consumer features, so no iCloud Mail address, no HomeKit, no Find My for the person's own devices. Admins hold roles and can reset passwords, suspend accounts and run audits.

One property matters more than people expect: the account is an organizational identity, so when an employee is offboarded in Entra ID, the Apple side follows.

Why it matters for a fleet

The classic mess on Apple fleets is personal Apple Accounts on company hardware. Someone enrolls their work iPhone with their own account, turns on Activation Lock, then leaves. The device is now a paperweight until that person answers an email. Managed Apple IDs remove the whole category of problem, and ABM gives you Activation Lock bypass on supervised devices.

Two deployment modes depend on them outright. User Enrollment on a BYOD iPhone will not start without a Managed Apple ID, because that account is what separates work data from personal data cryptographically. Shared iPad requires one per user to create the session partitions.

Watch the collision case. If an employee already used their work email address to create a personal Apple Account, ABM will flag the conflict and the user has to rename their personal account before the managed one can exist. On a 400-person rollout, plan a week for that alone.

How Appaloosa handles it

Appaloosa connects to Apple Business Manager, so the Managed Apple IDs and device assignments you maintain there drive enrollment, app assignment through Apple VPP and Custom Apps, and BYOD enrollment modes. Federation with your identity provider stays in ABM, where it belongs. The enrollment side is described on the iOS MDM page.

Explore

See the full platform

Enrollment, apps, security, remote support: all in one place.

Explore Appaloosa

See Appaloosa run on your fleet Book a demo

Frequently asked questions

Can a Managed Apple ID buy apps from the App Store?
No. Purchases, in-app purchases and Apple Pay are all blocked on a Managed Apple ID. Paid apps for a fleet go through Apple Business Manager volume purchasing and are assigned by your MDM, which is the behavior you want anyway since the licenses stay with the company.
What happens if an employee already uses their work email as a personal Apple Account?
Apple Business Manager detects the conflict and won't create the Managed Apple ID until it's resolved. The employee has to change the email address on their personal account, or accept a domain capture process. Budget time for this before a large rollout, because it always affects more people than expected.
Do we still need Managed Apple IDs if we federate with Entra ID?
Yes, federation doesn't replace them: it changes how they authenticate. The account still exists in Apple Business Manager and still carries the Apple-side capabilities, but the password lives in Entra ID and MFA is enforced there.