apple business manager w/Azure

Efff dd 576 Reputation points
2022-10-13T16:27:26.637+00:00

Hello
for the Federation with Azure do you use a ******@onmicrosoft.com account or do you use user@jaswant .com account?

should i create a service account for this Federation? with the AD Global Administrator, Application Administrator, or Cloud Application permissions

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
982 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. James Hamil 27,221 Reputation points Microsoft Employee Moderator
    2022-10-13T21:43:48.327+00:00

    Hi @Efff dd , from Apple's documentation:

    "Federated authentication requires that a user’s User Principal Name (UPN) match their email address. User Principal Name aliases and Alternate IDs aren’t supported."

    I would use the domain from your tenant for this. Please also follow our tutorial for this. For the permissions, it's up to you what you want to allow. For regular users I wouldn't grant any special permissions but if you're the owner I would recommend Global Admin. Please look through those docs and let me know if you have any questions.

    Thank you,
    James


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.