No Find My, no Siri, no iCloud Mail. Read the Managed Apple Account exclusions before you build a rollout on top of them.
A Managed Apple Account is an Apple identity your organisation designs, owns and manages, and it reaches a deliberately narrower set of Apple services than a personal account does. Apple publishes the full list, several entries surprise people, and every unchecked assumption on that list becomes a redesign later. We plan Apple identity for Indian organisations around what the account actually does, remotely from Hyderabad.
- 9 rolesDetermining what each user can access
- 4 usersHard cap on the Administrator role
- Browse onlyApp Store, iTunes Store, Apple Books
- Org ownedThe account belongs to you, not the person
Four questions that decide how much work this is.
The answers come back quickly, and together they tell you whether this is a fortnight of configuration or a quarter of identity work.
- Are your users signing into company Macs and iPhones with personal Apple Accounts today? That is the common answer in Indian estates, and it is why most Apple difficulty traces back to identity rather than devices: company data syncing to personal iCloud, and Activation Lock held by accounts you cannot administer.
- Is your identity provider linked to Apple Business yet? Where Microsoft Entra ID or Google Workspace is connected, Managed Apple Accounts are created automatically for users, which removes provisioning as a task. Where it is not, that link is the first real piece of work.
- How many domains and subdomains does the organisation actually use? Domains are individually managed and subdomains are treated as separate entities needing their own setup, so a group with several mail domains has more configuration ahead than one clean domain does.
- Which Apple services do your people believe they will have? Find My, Siri, iCloud Mail and the media services are excluded, and purchasing is browse-only. Every assumption on that list that goes unchecked now becomes a redesign after rollout.
Eight things to establish before you create the first one.
The organisation owns the account
Apple describes these as accounts organisations design, own and manage for the productivity of employees, instructors and students. That ownership is the entire point: the identity survives the person leaving, the company controls what it reaches, and offboarding becomes a controlled action rather than a request to a former employee.
Nine roles, and one is capped at four people
Roles determine what each user can access, across nine of them ranging from Administrator, with the most privileges, down to Student. The Administrator role is limited to four users. That is a hard cap, and deciding who holds those four seats, and what happens when one resigns, belongs in the design rather than in a surprise.
Four ways accounts get created
Manually, through federated authentication with Google Workspace or Microsoft Entra ID, by syncing with OpenID Connect or SCIM, and in Apple School Manager by importing from a student information system or uploading CSV files. For most Indian organisations already on Microsoft 365 or Google Workspace, federation is the route to aim for.
Federation creates accounts automatically
When Apple Business and your identity provider are linked, Managed Apple Accounts are created automatically for users. Provisioning stops being a task and becomes a property of the directory you already run, and the Apple identity stays aligned with the Entra ID or Google identity as people join, move and leave.
The exclusions that change plans
Health, Siri, Home, Find My, Journal and iCloud Family Sharing are not accessible on a Managed Apple Account. Neither are iCloud Mail or the iCloud+ services of Private Relay, Hide My Email and Custom Email Domain. The media services, Apple Music, Apple TV+, Apple Arcade and Apple Fitness+, are excluded too.
What works, including things people assume do not
iCloud services and Continuity across devices, including Calendar, Contacts, iCloud Drive, Photos, Notes and Safari. AirDrop, Handoff, Universal Clipboard, Sidecar and iPhone Mirroring. The Apple Developer Program, App Store Connect, Xcode Cloud and TestFlight. iMessage and FaceTime are turned on by default, and documents collaborate in Keynote, Pages, Numbers, Reminders and Notes.
Browse, but not purchase
In the App Store, iTunes Store and Apple Books, users on these accounts can browse but not purchase. Paid applications therefore arrive through volume purchasing and your management platform rather than through individuals buying what they need, which is a procurement change as much as a technical one.
Administrators decide which services are on
Administrators can modify access requirements and configure which services are available, so the default service set is a starting position rather than a fixed one. Recording a reason for each decision produces an access posture you can explain to a security reviewer or a client questionnaire without reconstruction.
Three exclusions reshape deployments more than all the others combined.
Apple publishes the service list plainly. These are the three entries that most often collide with a plan somebody already made.
- Find My is not accessible with a Managed Apple Account. If the plan for lost devices was the consumer Find My feature, it needs replacing with your management platform's lost mode, which is a different capability with different prerequisites and has to be designed, not assumed.
- Siri is not accessible either. Where voice interaction was part of the case for the devices, in accessibility scenarios or hands-free field work, that constraint belongs in the decision, not in a footnote discovered after procurement.
- iCloud Mail is unavailable, along with Private Relay, Hide My Email and Custom Email Domain. Mail comes from the platform you already run, which for most Indian organisations is Microsoft 365 or Google Workspace and is what they wanted anyway, but the assumption is worth testing out loud.
- And purchasing is browse-only across the App Store, iTunes Store and Apple Books, which makes volume purchasing through your management platform the only route for paid apps. That is a process change for teams used to buying and expensing.
Four things that stop an Apple identity project stalling.
We test the service list against your real requirements
Find My, Siri, Home, Health, Journal, iCloud Family Sharing, iCloud Mail, the iCloud+ services and the media services are all excluded. Establishing which of those somebody was quietly relying on takes an hour and prevents a design that cannot deliver what was promised to the business.
We plan around the four-Administrator cap
The Administrator role carries the most privileges and is limited to four users. We choose the four with you, record the reasoning, and agree the succession, so the cap is a design input rather than a discovery made when a fifth person needs access during an incident.
We enumerate every domain, including subdomains
Domains are individually managed and subdomains are treated as separate entities requiring their own setup. Indian groups with several brand domains or regional subdomains find this out partway through a rollout, when users on one of them cannot be created. We front-load the list.
We federate rather than create accounts by hand
Linked to Microsoft Entra ID or Google Workspace, Managed Apple Accounts are created automatically for users, and your existing directory remains the source of truth. Joiners get an Apple identity without a ticket, and disabling a leaver in the directory reaches the Apple estate too.
Four phases across roughly four to six weeks.
- 01Week 1· Week 1
Test expectations against the service list
Which Apple services people currently rely on, and which of those a Managed Apple Account can actually reach. Find My, Siri and iCloud Mail are the three most likely to be hiding inside somebody's plan, and all three are excluded, so this hour of checking prevents the expensive kind of surprise.
- Required Apple services listed and checked against availability
- Find My dependency identified and a lost-device alternative designed
- Mail confirmed as staying on your existing platform
- App purchasing route confirmed as volume purchasing
- 02Week 2· Week 2
Design the identity model
Federation with Microsoft Entra ID, Google Workspace or another provider, or synchronisation through OpenID Connect or SCIM. Every domain enumerated for its own setup, because subdomains are treated as separate entities rather than inheriting from the parent.
- Federation or sync route chosen with the identity provider
- Every domain and subdomain enumerated for separate setup
- Existing personal Apple Account conflicts on company domains identified
- Account creation approach agreed and documented
- 03Week 3· Week 3
Assign roles deliberately
Roles determine what each user can access, and the Administrator role is capped at four users. Choosing those four, and planning the succession when one leaves, is an organisational decision, not a technical one, and it is far easier made now than during a resignation.
- Role model designed across the nine available roles
- The four Administrator seats chosen with reasoning recorded
- Federation management accounts identified separately
- Role review and succession process agreed
- 04Weeks 4-6· Weeks 4-6
Configure services and roll out
Administrators configure which services are available, so the service set is decided rather than accepted. Then rollout, with user guidance that says plainly what the account does and does not do, which removes most of the first week's support questions before they are asked.
- Service availability configured deliberately, reasons recorded
- Federation enabled and account creation validated end to end
- User guidance issued covering the exclusions
- Support runbook for account and sign-in issues
Six situations where the account model decides the outcome.
A company whose Macs run on personal Apple Accounts
Personal accounts mean no control over service access, no recovery of the account at exit, and company files syncing to personal iCloud. Moving to Managed Apple Accounts is the correction, and communicating the service exclusions honestly is part of making the move stick.
An organisation federating with Microsoft Entra ID
Most Indian corporates already run Entra ID as the identity source. Linking it to Apple Business creates Managed Apple Accounts automatically, which removes provisioning as a task and is usually the single strongest reason to do this work now rather than later.
A school importing from its student system
Apple School Manager supports creating accounts by importing from a student information system or uploading CSV files, alongside federation. Where the authoritative student record lives in the school ERP rather than a directory, that import route is what makes the model workable.
A regulated firm restricting what devices reach
Administrators can configure which services are available, and several are excluded by default anyway. For NBFCs, brokers and other supervised firms, that combination produces a defensible, documentable position on what a corporate Apple device can and cannot connect to.
A company that planned around Find My
Find My is not accessible with a Managed Apple Account, so lost-device recovery must come from the management platform instead. Organisations that assumed the consumer feature need that redesigned before deployment, not after the first MacBook goes missing in transit.
A team distributing paid applications
Users can browse but not purchase in the App Store, iTunes Store and Apple Books, so paid apps come through volume purchasing and your management platform. That turns app distribution into a procurement process rather than a stream of individual reimbursement claims.
How Indian organisations handle Apple identity.
| Feature | Federated Managed Apple Accounts | Manually created managed accounts | Personal Apple Accounts |
|---|---|---|---|
Organisation owns the account | Yes | Yes | No |
Created automatically | Yes, from the directory | No | By the user |
Aligned with directory identity | Yes | Manually | No |
Service access controlled | Yes | Yes | No |
Purchasing restricted | Browse only | Browse only | Unrestricted |
Survives the person leaving | Yes | Yes | No |
Provisioning effort | None ongoing | Per user | None, but uncontrolled |
Find My available | No | No | Yes |
Lost-device recovery route | Management platform | Management platform | Personal Find My |
Suitable for corporate devices | Yes | Yes | No |
What a Managed Apple Account can and cannot reach.
| Service | Available to a Managed Apple Account | |
|---|---|---|
| iCloud Drive, Photos, Notes, Calendar, Contacts | Yes, with Continuity across devices on the same account | |
| AirDrop, Handoff, Universal Clipboard, Sidecar, iPhone Mirroring | Yes | |
| iMessage and FaceTime | Yes, turned on by default | |
| Document collaboration in Keynote, Pages, Numbers | Yes, plus Reminders and Notes | |
| Apple Developer Program, App Store Connect, Xcode Cloud, TestFlight | Yes | |
| Find My, Siri, Home, Health, Journal | No | |
| iCloud Mail | No | |
| iCloud+ services: Private Relay, Hide My Email, Custom Email Domain | No | |
| Apple Music, Apple TV+, Apple Arcade, Apple Fitness+ | No | |
| Purchasing in App Store, iTunes Store, Apple Books | Browse only, no purchasing |
Five steps, and the first is expectation testing.
- 1
Check required services against availability
Week 1
Health, Siri, Home, Find My, Journal, iCloud Family Sharing, iCloud Mail, the iCloud+ services and the media services are all excluded, and purchasing is browse-only. Establishing which of those anyone assumed is the first and most valuable conversation of the whole project.
- 2
Design the identity and domain model
Week 2
Federation with Microsoft Entra ID, Google Workspace or another provider, or synchronisation through OpenID Connect or SCIM. Every domain enumerated separately, because subdomains are distinct entities requiring their own setup rather than inheriting from a parent.
- 3
Design the role model inside the cap
Week 3
Nine roles, with the Administrator role limited to four users. One deliberate wrinkle to plan for: users whose role permits configuring federation cannot themselves sign in using federated authentication, so the federation managers are identified as a separate population.
- 4
Configure service availability deliberately
Week 3-4
Administrators can modify access requirements and configure which services are available, so the default set is a starting point. We decide each service with you and record the reason, producing a posture you can hand to a security reviewer or a client questionnaire.
- 5
Enable, validate and brief users
Weeks 4-6
Federation switched on and account creation validated end to end, then user guidance covering what the account does and does not do. The exclusions generate predictable questions, and answering them in writing beforehand removes most of the first week's support volume.
What Indian organisations ask about Managed Apple Accounts.
Fifteen questions worth answering first.
Service expectations
- Do we rely on Find My for lost devices?Not available on these accounts.
- Is Siri part of any use case?Also not available.
- Did anybody assume iCloud Mail?It is excluded.
- Do users need to buy apps themselves?They can browse, not purchase.
- Are any media services expected?Music, TV+, Arcade and Fitness+ are excluded.
Identity
- Which identity provider are we federating with?Entra ID, Google Workspace or another.
- Have we listed every domain?Subdomains need their own setup.
- Do staff hold personal Apple Accounts on our domain?A common conflict to resolve first.
- Are we syncing with OIDC or SCIM instead?Both are supported routes.
- Who manages the federation itself?Those users cannot sign in federated.
Roles
- Who holds the four Administrator seats?A hard cap, so choose deliberately.
- What happens when one of them resigns?Plan the succession now.
- Are the lower roles used appropriately?Nine are available.
- Is role assignment reviewed on a schedule?It drifts otherwise.
- Which services will we switch on?Administrators configure this, with reasons recorded.
The pages around this one.
Apple Business migration
The platform these accounts are managed from, and what changed in April 2026.
Learn moreApple School Manager
The education equivalent, with student information system import and Shared iPad.
Learn moreApple Platform SSO
Signing into the Mac itself with your Entra ID credentials, the layer above the account.
Learn moreList the Apple services your users expect, then check them against the exclusions.
Find My, Siri, iCloud Mail and the media services are all unavailable on a Managed Apple Account, and purchasing is browse-only. That comparison takes an hour and reshapes more Apple deployments than any other single check. Enquiries answered within 4 business hours, and managed clients work under a 30 minutes response SLA.