How to block Apple ID with Intune?

Federico Coppola 80 Reputation points
2024-03-28T09:53:12.44+00:00

Dear folks,
I am managing some iPAD devices with MS Intune.
This devices are "corporate" devices, not "personal" device.

How can I "deny" the usage of Apple ID?
I would "greyed out" option that permit to end user to login/create account on Apple ID.

Thanks!

Microsoft Intune iOS
Microsoft Intune iOS
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.iOS: An Apple mobile operating system.
186 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,336 questions
0 comments No comments
{count} votes

Accepted answer
  1. glebgreenspan 1,215 Reputation points
    2024-03-28T16:58:28.7633333+00:00

    Hello Federico

    If you want to restrict or prevent users from signing in or creating an Apple ID on corporate-managed iPads using Microsoft Intune, you can achieve this by configuring restrictions on the device using Intune policies. Here's how you can prevent users from signing in or creating an Apple ID:

    Create and Assign a Device Restrictions Policy:

    In the Microsoft Endpoint Manager admin center, navigate to "Devices" > "Configuration profiles" > "Create Profile".
    
       Select the device platform as "iOS/iPadOS".
      
          Under the "Settings" section, look for the option related to iCloud or Apple ID. The exact name may vary, but it typically falls under the "Restrictions" or "Device restrictions" category.
         
             Configure the setting to restrict iCloud or Apple ID sign-ins. This may involve disabling the option to Sign in with an Apple ID, Preventing iCloud Keychain, Disabling iCloud Photo Library, etc.
            
                Save the policy and assign it to the group containing the corporate iPad devices.
               
               **Deploy the Policy to Devices**:
               
                   Once the policy is created and configured, assign it to the group that includes the corporate iPad devices. The policy will be pushed to the devices, enforcing the restrictions set in the policy.
                  
    

    Device Compliance Check:

    Ensure that the devices are compliant with the policy and that the settings are applied correctly. You can check the compliance status of the devices in the Microsoft Endpoint Manager admin center.
    
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. ZhoumingDuan-MSFT 7,750 Reputation points Microsoft Vendor
    2024-03-29T06:00:47.1466667+00:00

    @Federico Coppola, Thanks for posting in Q&A.

    From your description, I know you want to block permit to end user to login/create account on Apple ID.

    After researching, there's a setting under Device Restriction policy may help. Device Restrictions > General > Block modification of account settings, it appears to grey out the option and not allow the user to create new account.

    https://learn.microsoft.com/en-us/mem/intune/configuration/device-restrictions-ios#settings-apply-to-automated-device-enrollment-supervised-6

    Hope above information will help.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.