Use Managed Apple IDs in Apple Business Manager Flashcards

https://support.apple.com/en-ph/guide/apple-business-manager/axm78b477c81/web

1
Q

Which Apple software makes it easy for organizations to create and manage Managed Apple IDs (owned and managed by your organization—including password resets and role-based administration. It also provides access to iCloud for collaboration with iWork and backup on iPhone and iPad devices)

A

Apple Business Manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which one of these is used to access personal data such as Photos, iMessages, and other personal iCloud data when signed in to a personal device?

A. Managed Apple ID
B. Personal Apple ID

A

B. Personal Apple ID

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A user with a Managed Apple ID can be locked out of their account if they enter an incorrect password more than _____ times or if Apple suspects any fraudulent activity on their account

A

10

To reset their password, the user must contact any user with the role of Administrator or People Manager. For users locked due to suspected fraudulent activities, an Apple Business Manager user with the role of Administrator must contact Apple to have the account unlocked. At that point, the user’s password can be reset by the Administrator.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the process of using a user account’s user name and password from one directory system allowing the same user name and password to be used in other systems?

A

federated authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the 2 types of Apple IDs

A

Managed Apple ID
Personal Apple ID

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How are Managed Apple IDs created? (4 ways)

A
  1. Configure and enable federated authentication with Google Workspace, Microsoft Entra ID, or your identity provider (IdP)

Note: If your organization is using federated authentication, the Default Managed Apple ID Format setting doesn’t apply.

  1. Sync with Google Workspace
  2. Sync using Open ID Connect (OIDC) with Microsoft Entra ID or your IdP
  3. Sync using System for Cross-domain Identity Management (SCIM) with your IdP

Important: Keep in mind that every Managed Apple ID must be unique. It also can’t be the same as other Apple IDs that other users may already have.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

As any user with the role of Administrator or any Manager, you use Managed Apple IDs in two main ways — with ____ and ____

A
  • Accounts: Users with the role of Administrator can complete a range of tasks within Apple Business Manager to manage accounts. For example, you can assign roles or reset passwords for a specific set of users.
  • Roles: After a Managed Apple ID is created for a user, roles can then be assigned for the user. These roles define which tasks users can perform in Apple Business Manager with their Managed Apple ID.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Can you change the Managed Apple ID of a user with the role of Administrator?

A

No

You must first change the role to any other role, change the Managed Apple ID, then change the role back to that of Administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A user’s changed/edited Managed Apple ID won’t be updated if?

A

If the new format includes an element that’s missing or empty for that user

Newly edited Managed Apple IDs changes the Managed Apple ID format for all new and existing accounts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Users are notified when their Managed Apple ID is changed

A. True
B. False

A

B. False

Users aren’t notified when their Managed Apple ID is changed, so you must notify them as soon as you make the change.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

When changing a Managed Apple ID, what happens when a new format results in a Managed Apple ID that’s already in use?

A

a number is added to the end of the new Managed Apple ID to make it unique

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the steps for editing a Managed Apple ID format for a single user?

A
  • In Apple Business Manager , sign in with a user that has the role of Administrator or People Manager.
  • Select Users in the sidebar, then select or search for a user in the search field.
  • Select the user from the list.
  • Select the Edit button , then edit the Managed Apple ID.

You can also enter text, such as a period (for example, eliza.block), in the field.

  • Select a domain from the list, then select Save.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the steps for editing the Managed Apple ID format for multiple users?

A
  • In Apple Business Manager , sign in with a user that has the role of Administrator or People Manager.
  • Select Users in the sidebar, then select or search for users in the search field.
  • Select the users from the list.
  • Select Edit next to Update Managed Apple IDs, then select the Add button to select what the Managed Apple ID will start with.

You can also enter text, such as a period (for example, eliza.block), in the field.

  • Select a domain from the list, then select Continue.
  • Do one of the following:
  1. Select Activity to view this activity.
  2. Select Done.

This task can be successfully completed only for users created manually.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

For Federated authenticaion

When Apple Business Manager and Google Workspace, Microsoft Entra ID, or your IdP are linked, Managed Apple IDs are automatically created for users

A. True
B. False

A

A. True

They can then sign in using their existing user name (generally their email address) and password.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

To use federated authentication and syncing, your Apple devices must meet what following minimum operating system requirements?

A
  • iOS 15.5
  • iPadOS 15.5
  • macOS 12.4
  • visionOS 1.1
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What will happen upon syncing Apple Business Manager with Google Workspace, Microsoft Entra ID, or your IdP after setting up a directory sync connection?

A

You can add Apple Business Manager properties (such as roles) with user account data imported from one of those services

The services’ user account information is added as read-only until you turn off syncing. At that time, the accounts become manual accounts, and attributes in these accounts can then be edited. If a user account is removed from one of those services, that user account can be removed from Apple Business Manager

17
Q

What can you do if a user forgets their passcode on a Shared iPad account

A

The administrator must reset the Shared iPad passcode

18
Q

When syncing user accounts from Google Workspace to Apple Business Manager, syncing user groups is supported

A. True
B. False

A

B. False

You can sync user accounts from Google Workspace into Apple Business Manager. When this occurs, you merge Apple Business Manager properties (such as roles) with user account data imported from Google Workspace. The account information is added as read-only until you turn off syncing. At that time, the accounts become manual accounts, and attributes in these accounts can then be edited.

The initial sync takes longer to perform than subsequent cycles.

19
Q

To use Managed Apple IDs, you must verify the domains you want to use, or you can use the reserved domain

A. True
B. False

A

A. True

Domains (also known as domain names) designate the larger organization rather than an individual member. Domain names are registered and must be globally unique.

20
Q

What ensures that your organization—and no one else—can use the domain you entered to create Managed Apple IDs?

A

Domain verification

For example, to use theacmeinc.com as your domain, you must add a specific TXT record—a type of Domain Name System (DNS) record—to your domain name server’s zone file within 14 calendar days of beginning the verification process (which begins when you select the Verify button).This indicates your organization has the authority to modify the domain name service (DNS) records for your domain.

21
Q

You have only ____ calendar days to complete the Domain verification process or you must start over.

A

14

Depending on the network configuration, it may take some time for DNS changes to appear. Make sure you’ve notified the person in your company who can write records to your DNS entries (for example, your IT or DNS administrator) so the task can be completed before the expiration.

22
Q

If you’re unable to verify your domain, what can you use?

A

Reserved domain

The reserved domain:

Is a domain that Apple generates automatically

Is based on the website that you used when you successfully signed up

Can’t be edited or removed

Doesn’t require the organization to verify the domain

23
Q

if you enrolled using the website www.theacmeinc.com, the reserved domain name would be?

A

theacmeinc.appleid.com

If multiple organizations use the same domain, an incremental number is added to the name, such as theacmeinc2.appleid.com

24
Q

What are the 2 types of domain conflicts?

A
  1. A domain that’s registered by another organization.
  2. A domain that’s registered by another organization and they verified it with Apple.

In Example 1, Your organization can choose to send their contact information (the name of the person requesting to be contacted, their email address, and the name of their company) to the organization that registered the domain name. That organization can choose whether or not to contact your organization to resolve the domain claim.

In Example 2, Your organization can’t send anything to their organization because it’s registered and they verified it with Apple. Therefore your organization can’t use the domain name.

25
Q

Apple intervenes in domain claims

A. True
B. False

A

B. False

Apple doesn’t intervene in domain claims.

26
Q

In Apple Business Manager, what are the steps to adding a domain?

A

In Apple Business Manager , sign in with a user that has the role of Administrator or People Manager.

Select your name at the bottom of the sidebar > Preferences > Managed Apple IDs .

In the Domains section, select Add Domain, then enter the domain you want to use.

Follow onscreen instructions

27
Q

What records contain information about your domain that helps external network servers and services handle outgoing email from your domain?

A

TXT record

28
Q

When a user account is synced from Google Workspace, Microsoft Entra ID using OIDC, or IdP using SCIM to Apple Business Manager, what is the default role?

A

Staff

This attribute is stored with the user account in Apple Business Manager and isn’t written back to Google Workspace

User groups from your IdP aren’t synced to Apple Business Manager. If you want the same groups, you can create new groups in Apple Business Manager and add users to them

Don’t reuse a user name for 30 days in the Apple Business Manager Entra ID app

29
Q

Apple Business Manager requires that the attribute used for the Managed Apple ID be unique. This is normally the user’s email address.

What happens If a user has an attribute that’s exactly the same as an existing Apple Business Manager user with the role of Administrator

A

No syncing is performed and the source field remains unchanged.

30
Q

When a Google Workspace user account is synced to Apple Business Manager, a ____ is created for the Apple Business Manager user account (to identify conflicting user accounts)

A

Person ID

31
Q

What are the steps to turn on Google Workspace Sync

A
  1. In Apple Business Manager , sign in with a user that has the role of Administrator or People Manager.
  2. Select your name at the bottom of the sidebar > Preferences > Managed Apple IDs
  3. Under Directory Sync, turn on Google Workspace Sync.
32
Q

What are the steps to turn on Microsoft Entra Connect Sync

A
  1. In Apple Business Manager , sign in with a user that has the role of Administrator or People Manager.
  2. Select your name at the bottom of the sidebar > Preferences > Managed Apple IDs
  3. Turn on Microsoft Entra Connect Sync then select Sync Now.
33
Q

Continuity services availability

Which Continuity features can users use between devices that are signed in with the same Managed Apple ID as the primary account on both devices?

A

AirDrop

AirPlay to Mac

Auto Unlock

Continuity Camera

Continuity Markup and Sketch

Handoff

Personal Hotspot

iPhone cellular calls

Sidecar

Universal Clipboard

Universal Control

34
Q

Due to the organizational focus and to protect user privacy, which services are not available for Managed Apple IDs?

A

Find My - The app appears, but the user can’t use it.

Health - The app can be used, but data isn’t synced to iCloud.

Home - The user can’t add HomeKit devices to the Home app.

Journal - The app appears, but the user can’t use it.

Apple Wallet - The app appears, but organizations can add only student ID cards and employee badges.

iCloud Family Sharing - Unavailable.

iCloud Mail - Unavailable.

iCloud+ services (Private Relay, Hide My Email, Custom Email Domain) - Unavailable.

35
Q

Scenario: A user is signed in to a device with a Managed Apple ID

Which media services are unavailable to the user?

A

Apple Arcade

Apple Fitness+

Apple Music

Apple Music radio

Apple News+

Apple One

Apple TV+

36
Q

Scenario: A user is signed in to a device with a Managed Apple ID

Which iCloud services are available to the user?

A

Calendar

Contacts

Freeform

iCloud Backup

iCloud Drive

iCloud Keychain

News

Notes

Photos

Reminders

Safari

Siri

Stocks