Jamf Pro supports Get Token requests from devices when access management controls for Managed Apple Accounts are enabled in Apple Business or Apple School Manager. When configured in Jamf Pro and with Apple, access management controls can limit Managed Apple Account sign-in to managed or supervised devices only. You can use the Jamf Pro API to define a specific MDM server object to use in the Get Token response, using the v4/enrollment/access-management API endpoint. A future version of Jamf Pro will enable this capability in the Jamf Pro interface.
- Ability to restrict Managed Apple Accounts access to managed or supervised devices only
- Enhanced security control over organizational data
- Granular management of Apple service access
- Improved compliance with organizational security policies
- Ensure all devices meet the minimum OS requirements.
- Communicate changes to users before enabling access controls.
- Maintain regular backups of device data during implementation.
Enabling access management controls can impact existing device sign-ins by a Managed Apple Account. Users may be signed out if devices do not meet the specified requirements. Ensure that all requirements are met prior to enabling access management controls.
Known Issue
The following known issue should be taken into consideration before enabling access management controls in Apple Business or Apple School Manager:
[PI136113] (Third-Party Issue) Users cannot sign in to Shared iPad devices using Managed Apple Accounts when access management is configured to require managed or supervised devices.
Customize user access to apps and services using Apple Business in Apple Business User Guide
Customize user access to certain apps and services using Apple School Manager in Apple School Manager User Guide
Jamf Pro 11.18.0 or later
An MDM server token from Apple Business or Apple School Manager configured in Automated Device Enrollment
macOS 14, iOS 17 or iPadOS 17 or later
On macOS, users attempting to sign in to their Managed Apple Account in the System Settings app must be using an MDM-enabled user account. This is because Get Token requests and responses between the computer and Jamf Pro occur over the user channel for MDM communications. This does not apply to macOS sign-in with a Managed Apple Account during account-driven Device Enrollment.