Setup Apple Business Manager for automatic user provisioning

In this blog we will look at the steps required to setup automatic user provisioning.

You can refer to this blog on the steps required to setup Apple Business Manager: Setup Apple Business Manager in Intune – Azure Cloud & AI Domain Blog (azurecloudai.blog)

Prerequisites

Before we get started we need to make sure we have the below prerequisites in place.

  • An Azure AD tenant.
  • A user account in Azure AD with permission to configure provisioning
  • An Apple Business Manager account with the role of Administrator or People Manager.
  • Domain Verified in Apple Business Manager

Verify your domain in Apple Business manager

  1. Sign into Apple Business Manager with an account that has the role of Administrator or People Manager.
  2. Click Settings at the bottom left and click Accounts under Organization Settings, then click Edit next to Domains.
    Graphical user interface, application

Description automatically generated
  3. Click Verify next to the domain.
  4. Add the TXT Record to your external DNS and click Check Now to verify the domain.

Note. If any of your domain account have previously been registered as an Apple ID you will get a warning and will be able to send a notification to those accounts. Thereafter you can enable the federation.

Setup Apple Business Manager to support provisioning with Azure AD

  1. Sign into Apple Business Manager with an account that has the role of Administrator or People Manager.
  2. Click Settings at the bottom left and click Data Source under Organization Settings, then click Connect to Data Source.
  3. Click Connect next to SCIM and click Copy to copy the token, then click Close.
    Graphical user interface, text, application, email

Description automatically generated

Add Apple Business Manager from the Azure AD application gallery

  1. Sign into the Azure Portal and navigate to Enterprise Applications.
  2. Select New Application and search for Apple Business Manager.
  3. Select Apple Business Manager and click Sign up for Apple Business Manager
    Graphical user interface, text, application

Description automatically generated
  4. In the applications list, select Apple Business Manager.
    Graphical user interface, text, application

Description automatically generated
  5. Click on Provisioning.
    Graphical user interface, text, application

Description automatically generated
  6. Set the Provisioning Mode to Automatic.

Provisioning tab automatic

  1. Under the Admin Credentials enter the Tenant URL and Secret Token retrieved from Apple Business Manager. Click Test Connection to ensure Azure AD can connect to Apple Business Manager.

Token

  1. In the Notification Email field, enter the email address of a person or group who should receive the provisioning error notifications and check the checkbox – Send an email notification when a failure occurs.

Notification Email

  1. Click Save.
  2. Under the Mappings, select Synchronize Azure Active Directory Users to Apple Business Manager.
  3. Review the user attributes that are synchronized from Azure AD to Apple Business Manager in the Attribute Mapping section.
  4. Turn on the Provisioning Status.
    Provisioning Status Toggled On
  5. Select the users and/or groups that you would like to provision to Apple Business Manager by choosing the values in Scope:
    Provisioning Scope
  6. Click Save to start the initial synchronization of the user specified above.
    Saving Provisioning Configuration
  7. You can monitor the Provisioning by looking at the Logs
    Graphical user interface, text, application, email

Description automatically generated
  8. You will see the accounts provisioned in Apple Business Manager under Accounts
    Graphical user interface, text, application, chat or text message

Description automatically generated

User Experience

Now that the user accounts have been provisioned, the end user can Sign into their phone with their corporate email as an Apple ID.

  1. During the setup of the Apple ID on the device the user will enter their corporate email address as the Apple IDGraphical user interface, text, application

Description automatically generated
  2. The user will get a message to continue to the company authentication pageText

Description automatically generated
  3. The user will authenticate with their corporate passwordGraphical user interface, text, application, chat or text message

Description automatically generated
  4. Once the user has authenticated the Apple ID is setup and the user can access the Apple Services (App Store, iCloud etc.)
    Graphical user interface, text, application

Description automatically generated

Author