On iPads that are:
- enrolled with Intune using Automated Device Enrollment (ADE), and
- configured as Shared iPad (without user affinity),
an Apple ID is not required for users to sign in to the device itself. Instead, sign-in is based on either:
- Partitioned user access (Managed Apple ID)
- Shared iPad creates user partitions on the device.
- With Microsoft Entra federation to Apple Business/School Manager, users sign in using their Microsoft Entra username and password.
- This first sign-in automatically creates a Managed Apple ID that matches the Entra username, and the user then sets an alphanumeric passcode for their partition.
- After that, users only provide their Managed Apple ID and passcode to access their partition.
- No personal Apple ID is required on the device for sign-in.
- Temporary (guest) sessions
- If temporary sessions are enabled, users can sign in as Guest without any Managed Apple ID or password.
- When they sign out, all user data is deleted.
If iPads are still prompting for an Apple ID, common reasons are:
- The devices are not actually provisioned as Shared iPad in the ADE profile (for Shared iPad, the profile must:
- be ADE,
- be without user affinity, and
- have Shared iPad enabled).
- The prompt is for App Store / app installation, not for device sign-in. For example, if apps are not deployed via VPP/device licensing and rely on the App Store, iOS will still ask for an Apple ID to download or update apps.
- The environment is using Apple Configurator or user-affinity enrollment, where a normal Apple ID flow still applies for app deployment.
To avoid Apple ID prompts on Shared iPad:
- Ensure the ADE enrollment profile is configured as:
- Enroll without user affinity.
- Shared iPad enabled.
- Choose either:
- Guest access (temporary sessions), or
- Partitioned user access (Managed Apple ID via Entra federation or manually created Managed Apple IDs).
- Use device-based app deployment (for example via VPP/device licensing) so apps do not require a personal Apple ID to install.
Once correctly configured as Shared iPad with ADE and apps deployed via Intune, users should not need to sign in with a personal Apple ID to use the device.
References: