Jump to content

Recommended Posts

Posted
So we have set up Shared iPad and think it will work well for us. We have federated signs setup so the initial login is done with their office 365 creds. After this they can set up a passcode to access again or on another ipad. Is there anyway we can restrict this so they have to use their full logon each time rather than a passcode?
  • 2 weeks later...
Posted

Slight derail, though it is related (promise!)... I wanted set up the federated logon between our ASM and 365 so that we could provision accounts for students to login in to shared iPads so we could allow Internet access again. It seems ~70 people have created Apple IDs with their school accounts, meaning that when I try to set federation it warns me that I need to reclaim those IDs prompting them to change the email address they use.

 

It doesn't seem to tell me which accounts are going to be affected? I'd like to sit through them first and query whether it's going to be a problem.

Posted
we had this with 80+ accounts. You cant see who currently has an account. We went ahead and did it and informed staff that this was happening. They get 90 days to change to a new email address so up to them to act on it or not....
Posted (edited)
we had this with 80+ accounts. You cant see who currently has an account. We went ahead and did it and informed staff that this was happening. They get 90 days to change to a new email address so up to them to act on it or not....

 

How will it affect the itunes accounts etc that we use to provision VPP etc? Like, the Apple ID we log into ASM/VPP/Secure Inbox etc. That's [email protected]. Our MDM solution spans ~6 years of continual development, built on a foundation of not fully understanding how it works. In other words, our ASM/Meraki accounts are all over the place for the two schools we manage.

 

Considering I can prove ownership of a domain name, you'd think any matching email addresses using our domain name would not be any sort of data breach. Why can't/won't Apple show us so we can be confident it's not a problem?

Edited by Planehazza
Posted (edited)
How will it affect the itunes accounts etc that we use to provision VPP etc? Like, the Apple ID we log into ASM/VPP/Secure Inbox etc. That's [email protected]. Our MDM solution spans ~6 years of continual development, built on a foundation of not fully understanding how it works. In other words, our ASM/Meraki accounts are all over the place for the two schools we manage.

 

Considering I can prove ownership of a domain name, you'd think any matching email addresses using our domain name would not be any sort of data breach. Why can't/won't Apple show us so we can be confident it's not a problem?

This is because even though you may own the domain the account has been set up for, it's a personal account. Apple's strict privacy rules stop you from knowing this information on a personal account, if the account for this person has left your organisation and they are still using it they will get a message from Apple 90 days after you have federated forcing them to change the email address you use for this.

 

This will not affect your ASM login as this is a Managed Apple ID, when you have invited the previous VPP account into ASM that also became a Managed Apple ID.

 

Just to repeat myself from anther thread, a Managed Apple ID is not a login for an iPad.

Edited by Brimstone

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...