In this blog we will look at the steps required to setup automatic user provisioning.
You can refer to this blog on the steps required to setup Apple Business Manager: Setup Apple Business Manager in Intune – Azure Cloud & AI Domain Blog (azurecloudai.blog)
Prerequisites
Before we get started we need to make sure we have the below prerequisites in place.
- An Azure AD tenant.
- A user account in Azure AD with permission to configure provisioning
- An Apple Business Manager account with the role of Administrator or People Manager.
- Domain Verified in Apple Business Manager
Verify your domain in Apple Business manager
- Sign into Apple Business Manager with an account that has the role of Administrator or People Manager.
- In the left bottom click Your Account and select Preferences and Accounts, then click Edit next to Domains.
- Click Verify next to the domain.
- Add the TXT Record to your external DNS and click Check Now to verify the domain.
- Once verified click Edit in the Federate Authentication section.
- Select Microsoft Azure AD and click Connect.
- Sing in with your corporate account and click Accept the Apple Business Manager Permissions and the click Done.
Setup Apple Business Manager to support provisioning with Azure AD
- Sign into Apple Business Manager with an account that has the role of Administrator or People Manager.
- In the left bottom click Your Account and select Preferences, then click Directory Sync.
- Click Enable next to Microsoft Azure AD Sync.
- Keep the Token, we will use it in the next section.
Add Apple Business Manager from the Azure AD application gallery
- Sign into the Azure Portal and navigate to Enterprise Applications.
- In the applications list, select Apple Business Manager.
- Click on Provisioning and then click Get Started.
- Set the Provisioning Mode to Automatic.
- Under the Admin Credentials enter the Tenant URL and Secret Token retrieved from Apple Business Manager. Click Test Connection to ensure Azure AD can connect to Apple Business Manager.
- Click Save.
- Start the Provisioning by clicking Start Provisioning.
- You can monitor the Provisioning by looking at the Logs
- You will see the accounts provisioned in Apple Business Manager under Users
User Experience
Now that the user accounts have ben provisioned the end user can Sign in to their phone with their corporate email as an Apple ID.
- During the setup of the Apple ID on the device the user will enter their corporate email address as the Apple ID
- The user will get a message to continue to the company authentication page
- The user will authenticate with their corporate password
- Once the user has authenticated the Apple ID is setup and the user can access the Apple Services (App Store, iCloud etc.)
You must log in to post a comment.