Decide which domain to federate 2. Connect to Azure to verify identity/ownership 3. View Apple ID conﬂicts on your domain 4. Resolve Apple ID conﬂicts on your domain 5. Notify end users of conﬂicts 6. Turn on and test federation
at Azure’s capabilities, we realized we could add ANY domain that we control to our Azure accounts, and (with a little bit of work) in the Microsoft console. Examples: lsc.k12.in.us apple.lsc.k12.in.us ipadatlsc.org
ANY truly does mean ANY! All personally created staﬀ Apple IDs Old student Apple IDs Purchasing Apple IDs (ecommerce.apple.com) GSX Apple IDs (Service) Apple Developer Apple IDs Old Apple Conﬁgurator Apple IDs EVEN YOUR APNs CERT FOR MDM!
with your staﬀ before you get “Why did I get this email?” work tickets! Outline future beneﬁts (Schoolwork, backup, single set of credentials, etc…) Instruct users where they can get help resolving conﬂicting Apple IDs.
After 30 days, Apple nudges conﬂicted accounts by deactivating FaceTime and iMessage. After 60 days, Apple resolves conﬂicts by migrating them to temporary Apple IDs. For example: firstname.lastname@example.org becomes email@example.com