Posted on 02-19-2024 09:33 AM
I need to setup a few macs on a Windows eco-system. The Macs need to be connected to Active Directory but also the AD user must not be able to sign out of a managed apple id or create a local user account to sign in with their own personal apple id. Has anyone done this with Jamf?
Posted on 02-20-2024 05:10 AM
Posted on 02-20-2024 07:45 AM
Agree with you there - AD is ancient and you'll end up with more issues if you try to bind a Mac to AD.
We just block access to the Apple ID preference pane so users cannot sign in at all. Until Apple sort out Managed Apple IDs it's just not worth considering. I had a meeting with Apple in November 2023 and they said improvements to Managed Apple IDs is on the 2024 roadmap (as well as the ability to integrate them with an IdP)
Posted on 02-20-2024 08:10 AM
Ya, Managed AppleID's are basically pointless unless your organization uses iCloud services (pages, mail, etc).
I'm at a loss for words that you got apple to commit to anything that could be considered a roadmap. I'm sure it's less a commitment and more so an offhand comment, but giving a timeline is impressive lol.
Posted on 02-20-2024 08:51 AM
Yes I don't believe it for a second... they were at our head office and looking to get more business. I told them they were literally the only vendor left that we use who don't support our IdP (Okta). That's when they came out with the roadmap comment.
Pretty amazing in this day and age that critical platforms like Apple Business Manager cannot be hidden behind an IdP... but there you go.
Posted on 02-21-2024 01:51 PM
Is there a chance that they used the word "federate" and not integrate (Federation now supports OIDC in addition to Azure AD & Google Workspace).
Posted on 02-22-2024 02:00 AM
I've just spotted this and contacted our IdP about it - still in beta but definitely a step in the right direction.
Posted on 02-20-2024 09:47 AM
Thank you for the insight. The CFO does not want MAC into a MS ecosystem unless it would be tied to Azure SSO. Also does not want end users to upload to icloud any data but still use iMessage using a corporate Apple Managed ID. I guess all of this is just screwed
Posted on 02-20-2024 02:13 PM
It's possible via a Configuration Profile to restrict iCloud data (Drive, Mail, Keychain etc) but as mentioned before, Managed Apple IDs are just not fit for purpose and there's nothing stopping an end user from signing in with a personal Apple ID.
In regards to your CFO requirements it might be worth checking out Jamf Connect or in the very near future Platform SSO to bind your Macs to an IdP. Azure is not always the answer :-)