Skip to main content

Enrollment SSO with Managed Apple ID - Device-side experience

Updated this week

For Enrollment SSO Device Management, users can enroll a device with their Managed Apple ID:

Good to know:

  • Enrollment SSO handles only the enrollment flow; it does not replace the macOS login window.

  • When an IdP is integrated with Apple Business Manager (ABM), you can keep the Managed Apple ID identical to the user’s Google email (or its domain alias), so identity stays consistent across Google Workspace and Apple services.

  • To enroll an Apple device, please follow the steps after the admin sets up the Enrollment SSO on Swif.

  • Device management and iCloud can NOT be the same email. If the Enrollment SSO is xxx@company.com, when I later log in to iCloud with xxx@company.com, iCloud can not log in.

Option 1: Sign in at the Device Management screen with a Managed Apple ID

  1. Go to Settings > Device Management > Sign in to a Work or School account, eg. xxx@{yourappleiddomain}

  2. Click Continue. It opens the Swif web page and confirms the user’s Managed Apple ID, xxx@{yourappleiddomain}

  3. Confirm the Email and Team name

  4. Sign in with the managed Apple account password that your Admin sent to you.

  5. Click Allow for the Remote Management.

  6. Enrollment profile installed successfully

Option 2: Sign in at the Device Management screen with a Federated Managed Apple ID with IdP

  1. Go to Settings > Device Management > Sign in to a Work or School account, eg. xxx@{yourappleiddomain}.

  2. Click Continue. It opens the Swif web page and confirms the user’s Managed Apple ID, xxx@{yourappleiddomain}. This should be an IdP federated work email, eg, a Google Workspace account that you linked on Apple Business Manager.

  3. Confirm the Email and Team name

  4. Redirect to IdP for SSO sign-in, eg, Google Workspace, when an IdP is integrated with Apple Business Manager (ABM).

  5. Allow Remote Management

  6. Enrollment profile installed successfully

Did this answer your question?