why Intune enrolled ipads still require an apple id to log in

Arthur Copeland 0 Reputation points
2026-03-19T11:29:30.7833333+00:00

why Intune enrolled ipads still require an apple id to log in and configured as shared devices

Microsoft Security | Intune | Microsoft Intune iOS
0 comments No comments

2 answers

Sort by: Oldest
  1. AI answer

    2026-03-19T11:29:44.2466667+00:00

    On iPads that are:

    • enrolled with Intune using Automated Device Enrollment (ADE), and
    • configured as Shared iPad (without user affinity),

    an Apple ID is not required for users to sign in to the device itself. Instead, sign-in is based on either:

    1. Partitioned user access (Managed Apple ID)
      • Shared iPad creates user partitions on the device.
      • With Microsoft Entra federation to Apple Business/School Manager, users sign in using their Microsoft Entra username and password.
      • This first sign-in automatically creates a Managed Apple ID that matches the Entra username, and the user then sets an alphanumeric passcode for their partition.
      • After that, users only provide their Managed Apple ID and passcode to access their partition.
      • No personal Apple ID is required on the device for sign-in.
    2. Temporary (guest) sessions
      • If temporary sessions are enabled, users can sign in as Guest without any Managed Apple ID or password.
      • When they sign out, all user data is deleted.

    If iPads are still prompting for an Apple ID, common reasons are:

    • The devices are not actually provisioned as Shared iPad in the ADE profile (for Shared iPad, the profile must:
      • be ADE,
      • be without user affinity, and
      • have Shared iPad enabled).
    • The prompt is for App Store / app installation, not for device sign-in. For example, if apps are not deployed via VPP/device licensing and rely on the App Store, iOS will still ask for an Apple ID to download or update apps.
    • The environment is using Apple Configurator or user-affinity enrollment, where a normal Apple ID flow still applies for app deployment.

    To avoid Apple ID prompts on Shared iPad:

    1. Ensure the ADE enrollment profile is configured as:
      • Enroll without user affinity.
      • Shared iPad enabled.
      • Choose either:
        • Guest access (temporary sessions), or
        • Partitioned user access (Managed Apple ID via Entra federation or manually created Managed Apple IDs).
    2. Use device-based app deployment (for example via VPP/device licensing) so apps do not require a personal Apple ID to install.

    Once correctly configured as Shared iPad with ADE and apps deployed via Intune, users should not need to sign in with a personal Apple ID to use the device.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

  2. Pauline Mbabu 1,840 Reputation points Microsoft Employee
    2026-04-17T10:47:54.31+00:00

    Hello Arthur,
    Intune enrolled iPads can still prompt for an Apple ID even when intended as shared devices because of how Apple’s platform security and app distribution models work together with Intune enrollment. For true Shared iPad scenarios, the device must be enrolled using Automated Device Enrollment without user affinity and explicitly configured as Shared iPad, where users sign in with Managed Apple IDs or via Microsoft Entra ID federation rather than personal Apple IDs, and guest access can also be enabled. If an Apple ID prompt appears, it is most commonly related to app installation or updates rather than device sign-in, for example when apps are not deployed using device based licensing through Apple Business Manager and Apple Volume Purchase Program, which forces the App Store to require an Apple ID. This behavior is by design from Apple and means personal Apple IDs are not required for Shared iPad sign in, but correct ADE configuration and device based app deployment are essential to avoid Apple ID prompts.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.