Introduction
This guide provides a step-by-step process to set up Apple Business Manager (ABM) Managed IDs federation by Google Workspace. This setup allows seamless integration and management of Apple ID using Google Workspace credentials.
Prerequisites
Access to Apple Business Manager (ABM) with admin privileges.
A Google Workspace account with admin access.
Domain ownership verification for the domain you wish to federate.
Steps to Set Up ABM Managed ID Federated by Google Workspace
Integrate Google SSO with ABM
At Step 5 of the Managed Apple ID setup, "Add Managed Apple ID to Apple Business Manager", instead of manually adding a Managed Apple ID, you can integrate Google Directory federation and enable Sign in with Google Workspace so that staff can log in using Google credentials.
Configure User Sign-In and Directory Sync
Enforce Google SSO
Enrollment SSO Sign-in with a Federated Managed Apple ID
Step-by-step guide of Enrollment SSO with a Federated Managed Apple ID
iCloud Sign-in with a Federated Managed Apple ID
Device management and iCloud can NOT be the same email. If the Enrollment SSO is xxx@company.com, when I later log in to iCloud with xxx@company.com, iCloud can not log in.
Users can now use their Google work email to sign in to iCloud automatically.
Upon signing in to iCloud with their company email, users will be redirected to Google Workspace for authentication.
Note, iCloud sign-in won't enroll the device in Swif. This is only for iCloud account login.
Conclusion
By following these steps, you can successfully set up ABM Managed IDs federated by Google Workspace, allowing for streamlined Managed Apple ID user authentication.