Skip to main content

Control Managed Apple Account Access in ABM and ASM

What access management controls

AApple newBusiness featureManager for iOS 17, iPadOS 17,(ABM) and Apple School Manager (ASM) let administrators control which devices, apps, and Apple services users can access with a Managed Apple Account. Apple introduced the expanded service controls with iOS 17, iPadOS 17, and macOS 1414.

from

This Apple,configuration Customiseis Usermanaged Accessin ABM or ASM.
It is not a FileWave profile payload. FileWave continues to manage the device, while Apple's portal controls Managed Apple IDsAccount service access.

Apple's access tocategories Apps and services.

Requires either Apple School or Business Manager

Access control includes:include:

  • iCloud features and Appapp data
  • FaceTime and iMessage
  • Apple Wallet
  • Apple Developer services
  • AppleSeed for IT
  • Device Signsign-in In eligibility
  • Privacy and Securitysecurity features

along with other features for instructors and students.

When

As of FileWave 15.5.0, Apple's required, new Get Token endpoint has been included.

Some features require the device is Managed, whilst other features require the devices to be Supervised.

Further details may be viewed from either:

    Apple School Manager Useralso Guideprovides -education-specific Customisecontrols Userfor Accessstudents and instructors.

    Plan the access policy

    Decide which services each role needs and which device states are acceptable before changing access. If a device no longer meets a newly selected management requirement, Apple can sign the Managed Apple Account out of that device.

    Pilot policy changes.
    Test with representative Managed Apple Accounts and devices before applying a new sign-in or service restriction broadly.

    Use Apple's current instructions for the portal you manage:

      Apple BusinessBusiness: ManagerCustomize Useruser Guideaccess -to Customiseapps Userand Accessservices

      InformationExample decisions

      Apple's Customise User Access offers admins much greater granular control over users andBuild the accesspolicy ofaround devices,the serviceswork andeach apps.Managed Apple Account must perform. Common decisions include:

      • PerhapsWhether itiCloud is desirableavailable, which iCloud features are allowed, and which app data can be stored there
      Whether Pages, Numbers, and Keynote collaboration is limited to blockusers iCloudin the organization Whether FaceTime, iMessage, Apple Wallet, Apple Developer, or AppleSeed for IT is available Whether Managed Apple Accounts can sign in on any supported device or only allowdevices iCloudthat on Managed devices.   Which Apps should be allowed to use iCloud?  Maybe organisational users should bemeet the onlyselected onesmanagement allowed to collaborate with Pages, Numbers or Keynote files. Should iMessage or FaceTime be allowed and if so, who should this include? Can an Apple ID log into all or only some devices?state

      ThenAvailability there'svaries examplesby ofservice, role, operating system, country or region, and device management regardingstate. developersCheck Apple's service-access tables before relying on a specific combination.

      After saving the policy in ABM or ASM, sign in with a pilot account and testing Apple OS releases and other options for students, instructors and security.

      The above features are all managed through the Apple Business or School Manager portal.  Please follow the links provided for configuration ofverify each feature.required service on a representative device.