Skip to main content
Managed Apple Accounts, India

No Find My, no Siri, no iCloud Mail. Read the Managed Apple Account exclusions before you build a rollout on top of them.

A Managed Apple Account is an Apple identity your organisation designs, owns and manages, and it reaches a deliberately narrower set of Apple services than a personal account does. Apple publishes the full list, several entries surprise people, and every unchecked assumption on that list becomes a redesign later. We plan Apple identity for Indian organisations around what the account actually does, remotely from Hyderabad.

  • 9 rolesDetermining what each user can access
  • 4 usersHard cap on the Administrator role
  • Browse onlyApp Store, iTunes Store, Apple Books
  • Org ownedThe account belongs to you, not the person
Start here

Four questions that decide how much work this is.

The answers come back quickly, and together they tell you whether this is a fortnight of configuration or a quarter of identity work.

  • Are your users signing into company Macs and iPhones with personal Apple Accounts today? That is the common answer in Indian estates, and it is why most Apple difficulty traces back to identity rather than devices: company data syncing to personal iCloud, and Activation Lock held by accounts you cannot administer.
  • Is your identity provider linked to Apple Business yet? Where Microsoft Entra ID or Google Workspace is connected, Managed Apple Accounts are created automatically for users, which removes provisioning as a task. Where it is not, that link is the first real piece of work.
  • How many domains and subdomains does the organisation actually use? Domains are individually managed and subdomains are treated as separate entities needing their own setup, so a group with several mail domains has more configuration ahead than one clean domain does.
  • Which Apple services do your people believe they will have? Find My, Siri, iCloud Mail and the media services are excluded, and purchasing is browse-only. Every assumption on that list that goes unchecked now becomes a redesign after rollout.
What a Managed Apple Account is

Eight things to establish before you create the first one.

The account is the identity foundation of an Apple deployment, and the service exclusions shape what your users can actually do with it. Most of the friction in a rollout traces back to an expectation somebody formed before anyone read the published service list.

The organisation owns the account

Apple describes these as accounts organisations design, own and manage for the productivity of employees, instructors and students. That ownership is the entire point: the identity survives the person leaving, the company controls what it reaches, and offboarding becomes a controlled action rather than a request to a former employee.

Nine roles, and one is capped at four people

Roles determine what each user can access, across nine of them ranging from Administrator, with the most privileges, down to Student. The Administrator role is limited to four users. That is a hard cap, and deciding who holds those four seats, and what happens when one resigns, belongs in the design rather than in a surprise.

Four ways accounts get created

Manually, through federated authentication with Google Workspace or Microsoft Entra ID, by syncing with OpenID Connect or SCIM, and in Apple School Manager by importing from a student information system or uploading CSV files. For most Indian organisations already on Microsoft 365 or Google Workspace, federation is the route to aim for.

Federation creates accounts automatically

When Apple Business and your identity provider are linked, Managed Apple Accounts are created automatically for users. Provisioning stops being a task and becomes a property of the directory you already run, and the Apple identity stays aligned with the Entra ID or Google identity as people join, move and leave.

The exclusions that change plans

Health, Siri, Home, Find My, Journal and iCloud Family Sharing are not accessible on a Managed Apple Account. Neither are iCloud Mail or the iCloud+ services of Private Relay, Hide My Email and Custom Email Domain. The media services, Apple Music, Apple TV+, Apple Arcade and Apple Fitness+, are excluded too.

What works, including things people assume do not

iCloud services and Continuity across devices, including Calendar, Contacts, iCloud Drive, Photos, Notes and Safari. AirDrop, Handoff, Universal Clipboard, Sidecar and iPhone Mirroring. The Apple Developer Program, App Store Connect, Xcode Cloud and TestFlight. iMessage and FaceTime are turned on by default, and documents collaborate in Keynote, Pages, Numbers, Reminders and Notes.

Browse, but not purchase

In the App Store, iTunes Store and Apple Books, users on these accounts can browse but not purchase. Paid applications therefore arrive through volume purchasing and your management platform rather than through individuals buying what they need, which is a procurement change as much as a technical one.

Administrators decide which services are on

Administrators can modify access requirements and configure which services are available, so the default service set is a starting position rather than a fixed one. Recording a reason for each decision produces an access posture you can explain to a security reviewer or a client questionnaire without reconstruction.

The exclusions in full view

Three exclusions reshape deployments more than all the others combined.

Apple publishes the service list plainly. These are the three entries that most often collide with a plan somebody already made.

  • Find My is not accessible with a Managed Apple Account. If the plan for lost devices was the consumer Find My feature, it needs replacing with your management platform's lost mode, which is a different capability with different prerequisites and has to be designed, not assumed.
  • Siri is not accessible either. Where voice interaction was part of the case for the devices, in accessibility scenarios or hands-free field work, that constraint belongs in the decision, not in a footnote discovered after procurement.
  • iCloud Mail is unavailable, along with Private Relay, Hide My Email and Custom Email Domain. Mail comes from the platform you already run, which for most Indian organisations is Microsoft 365 or Google Workspace and is what they wanted anyway, but the assumption is worth testing out loud.
  • And purchasing is browse-only across the App Store, iTunes Store and Apple Books, which makes volume purchasing through your management platform the only route for paid apps. That is a process change for teams used to buying and expensing.
Ask us to check your assumptions
How we approach it

Four things that stop an Apple identity project stalling.

Managed Apple Accounts are straightforward once expectations are correct. Nearly every difficulty we see began as an assumption about a service that was never available on this account type.

We test the service list against your real requirements

Find My, Siri, Home, Health, Journal, iCloud Family Sharing, iCloud Mail, the iCloud+ services and the media services are all excluded. Establishing which of those somebody was quietly relying on takes an hour and prevents a design that cannot deliver what was promised to the business.

We plan around the four-Administrator cap

The Administrator role carries the most privileges and is limited to four users. We choose the four with you, record the reasoning, and agree the succession, so the cap is a design input rather than a discovery made when a fifth person needs access during an incident.

We enumerate every domain, including subdomains

Domains are individually managed and subdomains are treated as separate entities requiring their own setup. Indian groups with several brand domains or regional subdomains find this out partway through a rollout, when users on one of them cannot be created. We front-load the list.

We federate rather than create accounts by hand

Linked to Microsoft Entra ID or Google Workspace, Managed Apple Accounts are created automatically for users, and your existing directory remains the source of truth. Joiners get an Apple identity without a ticket, and disabling a leaver in the directory reaches the Apple estate too.

How a deployment runs

Four phases across roughly four to six weeks.

The identity work carries most of the effort. Once federation is in place, account creation stops being a task and becomes a property of the directory.
  1. 01
    Week 1· Week 1

    Test expectations against the service list

    Which Apple services people currently rely on, and which of those a Managed Apple Account can actually reach. Find My, Siri and iCloud Mail are the three most likely to be hiding inside somebody's plan, and all three are excluded, so this hour of checking prevents the expensive kind of surprise.

    • Required Apple services listed and checked against availability
    • Find My dependency identified and a lost-device alternative designed
    • Mail confirmed as staying on your existing platform
    • App purchasing route confirmed as volume purchasing
  2. 02
    Week 2· Week 2

    Design the identity model

    Federation with Microsoft Entra ID, Google Workspace or another provider, or synchronisation through OpenID Connect or SCIM. Every domain enumerated for its own setup, because subdomains are treated as separate entities rather than inheriting from the parent.

    • Federation or sync route chosen with the identity provider
    • Every domain and subdomain enumerated for separate setup
    • Existing personal Apple Account conflicts on company domains identified
    • Account creation approach agreed and documented
  3. 03
    Week 3· Week 3

    Assign roles deliberately

    Roles determine what each user can access, and the Administrator role is capped at four users. Choosing those four, and planning the succession when one leaves, is an organisational decision, not a technical one, and it is far easier made now than during a resignation.

    • Role model designed across the nine available roles
    • The four Administrator seats chosen with reasoning recorded
    • Federation management accounts identified separately
    • Role review and succession process agreed
  4. 04
    Weeks 4-6· Weeks 4-6

    Configure services and roll out

    Administrators configure which services are available, so the service set is decided rather than accepted. Then rollout, with user guidance that says plainly what the account does and does not do, which removes most of the first week's support questions before they are asked.

    • Service availability configured deliberately, reasons recorded
    • Federation enabled and account creation validated end to end
    • User guidance issued covering the exclusions
    • Support runbook for account and sign-in issues
Where this matters

Six situations where the account model decides the outcome.

The recurring theme is an organisation that deployed Apple hardware before deciding whose accounts the devices would be signed into, and is now correcting that in production.

A company whose Macs run on personal Apple Accounts

Personal accounts mean no control over service access, no recovery of the account at exit, and company files syncing to personal iCloud. Moving to Managed Apple Accounts is the correction, and communicating the service exclusions honestly is part of making the move stick.

An organisation federating with Microsoft Entra ID

Most Indian corporates already run Entra ID as the identity source. Linking it to Apple Business creates Managed Apple Accounts automatically, which removes provisioning as a task and is usually the single strongest reason to do this work now rather than later.

A school importing from its student system

Apple School Manager supports creating accounts by importing from a student information system or uploading CSV files, alongside federation. Where the authoritative student record lives in the school ERP rather than a directory, that import route is what makes the model workable.

A regulated firm restricting what devices reach

Administrators can configure which services are available, and several are excluded by default anyway. For NBFCs, brokers and other supervised firms, that combination produces a defensible, documentable position on what a corporate Apple device can and cannot connect to.

A company that planned around Find My

Find My is not accessible with a Managed Apple Account, so lost-device recovery must come from the management platform instead. Organisations that assumed the consumer feature need that redesigned before deployment, not after the first MacBook goes missing in transit.

A team distributing paid applications

Users can browse but not purchase in the App Store, iTunes Store and Apple Books, so paid apps come through volume purchasing and your management platform. That turns app distribution into a procurement process rather than a stream of individual reimbursement claims.

Three positions

How Indian organisations handle Apple identity.

The right-hand column is where most estates start, and it produces the worst outcome at offboarding, because the account and everything synced under it belong to the individual rather than the company.
Feature
Federated Managed Apple Accounts
Manually created managed accounts
Personal Apple Accounts
Organisation owns the account
YesYesNo
Created automatically
Yes, from the directoryNoBy the user
Aligned with directory identity
YesManuallyNo
Service access controlled
YesYesNo
Purchasing restricted
Browse onlyBrowse onlyUnrestricted
Survives the person leaving
YesYesNo
Provisioning effort
None ongoingPer userNone, but uncontrolled
Find My available
NoNoYes
Lost-device recovery route
Management platformManagement platformPersonal Find My
Suitable for corporate devices
YesYesNo
The service list

What a Managed Apple Account can and cannot reach.

Taken from Apple's published service access documentation. Administrators can configure which services are available, so treat this as the starting position rather than a fixed one.
ServiceAvailable to a Managed Apple Account
iCloud Drive, Photos, Notes, Calendar, ContactsYes, with Continuity across devices on the same account
AirDrop, Handoff, Universal Clipboard, Sidecar, iPhone MirroringYes
iMessage and FaceTimeYes, turned on by default
Document collaboration in Keynote, Pages, NumbersYes, plus Reminders and Notes
Apple Developer Program, App Store Connect, Xcode Cloud, TestFlightYes
Find My, Siri, Home, Health, JournalNo
iCloud MailNo
iCloud+ services: Private Relay, Hide My Email, Custom Email DomainNo
Apple Music, Apple TV+, Apple Arcade, Apple Fitness+No
Purchasing in App Store, iTunes Store, Apple BooksBrowse only, no purchasing
How an engagement runs

Five steps, and the first is expectation testing.

The service exclusions are published and specific. Checking them against what your people actually expect is the cheapest possible way to avoid a redesign later.
  1. 1

    Check required services against availability

    Week 1

    Health, Siri, Home, Find My, Journal, iCloud Family Sharing, iCloud Mail, the iCloud+ services and the media services are all excluded, and purchasing is browse-only. Establishing which of those anyone assumed is the first and most valuable conversation of the whole project.

  2. 2

    Design the identity and domain model

    Week 2

    Federation with Microsoft Entra ID, Google Workspace or another provider, or synchronisation through OpenID Connect or SCIM. Every domain enumerated separately, because subdomains are distinct entities requiring their own setup rather than inheriting from a parent.

  3. 3

    Design the role model inside the cap

    Week 3

    Nine roles, with the Administrator role limited to four users. One deliberate wrinkle to plan for: users whose role permits configuring federation cannot themselves sign in using federated authentication, so the federation managers are identified as a separate population.

  4. 4

    Configure service availability deliberately

    Week 3-4

    Administrators can modify access requirements and configure which services are available, so the default set is a starting point. We decide each service with you and record the reason, producing a posture you can hand to a security reviewer or a client questionnaire.

  5. 5

    Enable, validate and brief users

    Weeks 4-6

    Federation switched on and account creation validated end to end, then user guidance covering what the account does and does not do. The exclusions generate predictable questions, and answering them in writing beforehand removes most of the first week's support volume.

Straight answers

What Indian organisations ask about Managed Apple Accounts.

Before you enable federation

Fifteen questions worth answering first.

The first group is where deployments most often discover a constraint late, because the services people assume are present are exactly the ones nobody thinks to verify.

Service expectations

  • Do we rely on Find My for lost devices?
    Not available on these accounts.
  • Is Siri part of any use case?
    Also not available.
  • Did anybody assume iCloud Mail?
    It is excluded.
  • Do users need to buy apps themselves?
    They can browse, not purchase.
  • Are any media services expected?
    Music, TV+, Arcade and Fitness+ are excluded.

Identity

  • Which identity provider are we federating with?
    Entra ID, Google Workspace or another.
  • Have we listed every domain?
    Subdomains need their own setup.
  • Do staff hold personal Apple Accounts on our domain?
    A common conflict to resolve first.
  • Are we syncing with OIDC or SCIM instead?
    Both are supported routes.
  • Who manages the federation itself?
    Those users cannot sign in federated.

Roles

  • Who holds the four Administrator seats?
    A hard cap, so choose deliberately.
  • What happens when one of them resigns?
    Plan the succession now.
  • Are the lower roles used appropriately?
    Nine are available.
  • Is role assignment reviewed on a schedule?
    It drifts otherwise.
  • Which services will we switch on?
    Administrators configure this, with reasons recorded.
Next step

List the Apple services your users expect, then check them against the exclusions.

Find My, Siri, iCloud Mail and the media services are all unavailable on a Managed Apple Account, and purchasing is browse-only. That comparison takes an hour and reshapes more Apple deployments than any other single check. Enquiries answered within 4 business hours, and managed clients work under a 30 minutes response SLA.