Managed AppleIDs, Wallet and tickets
(Initial explanation for others less familiar with this.)
Managed AppleIDs are AppleIDs created in an enterprise/education environment for use by users. These AppleIDs will be linked to a central directory service such as Azure AD (now known as Entra) or Google Workspace. One of these services would be synced to Apple Business Manager Or Education Manager so that AppleIDs are automatically created and the login is processed by the directory service using the password in that directory service.
This allows what is referred to as 'Single Sign-On' and for the IT admins to automatically add and remove access.
So far nothing different to see…
However Apple have limited the functions a Managed AppleID can use compared to a 'normal' standalone AppleID as would be created for example by a home user. See the following and scroll down to "Service access with Managed Apple IDs ".
Use Managed Apple IDs in Apple Business Manager – Apple Support (UK)
Now the fact some services are limited or not available on the surface makes sense. The issue I am interested in - the use of Apple Wallet being one of them. I as an IT Manager I would not necessarily want users to use organisation i.e. Managed AppleIDs to make purchases. However this in the form of Apple Pay is not the only function of the Wallet app. Another function is to allow other apps to store and display 'tickets' in the Wallet app, for example AirPlane tickets and as one user raised to me this week and is clearly not a work related issue - the storing of a Football ticket. (Soccer to our friends in the colonies.)
It seems that once more Apple have been too blunt with an otherwise good idea and blocked literally all uses of the Wallet app and not just purchasing. I can imagine that there might be other scenarios e.g. in the US the storage of ID cards and Student ID cards that might also as a result be blocked.
So, my first question is - I presume I am right in thinking that currently Managed AppleIDs literally block all uses of the Wallet app including tickets, loyalty cards and ID cards and not just Apple Pay and credit/debit cards.
My second question is if anyone has suggestion on how best to handle this?
One option I can see might be to not log the iPhone in to an iCloud account and to only log separately in to iMessages and FaceTime. This does mean not having access to other iCloud services but I believe should allow Wallet to be used. Arguably this means throwing out the baby with the bathwater - a solution Apple's often too blunt initial implementations of new 'security improvements' necessitates to make things actually useful.
My third question is that one major use of Managed AppleIDs will be inconjunction with BYOD enrolment. I presume here the expectation is that the BYOD device will be logged in to a personal iCloud account and the Managed AppleID will be used somewhat like above for select services including the special form of device enrolment for BYOD devices. Clearly end users are not going to accept loosing significant functionality of their own personal devices.
User Enrolment and MDM – Apple Support (UK)
Note: In the case of my query, this relates to only organisation owned devices - not BYOD devices.
iPhone 11