SOP — Provision a Company Apple Account, Apple Business (ABM), and a Corporate Google Account for Managed Google Play
| Version | 1.0 |
| Date | 2026-06-22 |
| Tenant context | mptwork.com (mptwork.onmicrosoft.com) |
| Purpose | Create the three organization accounts that Intune needs to manage Apple and Android devices |
| Companion SOP | Device management — sop-manage-devices-intune-mptwork.md |
Recency note (June 2026): On April 14, 2026, Apple Business Manager became "Apple Business" (it now combines the old Apple Business Manager, Apple Business Essentials, and Apple Business Connect) — still at business.apple.com. In the United States, the D-U-N-S number is no longer required for verification; Apple now uses the Federal Taxpayer Identification Number (EIN/TIN). Other countries use country-specific identifiers (a D-U-N-S number may still apply). Older guides will say "Apple Business Manager" and "D-U-N-S required" — the steps below reflect the current flow.Accounts you will create
| # | Account | Example | Purpose |
|---|---|---|---|
| 1 | Company Apple Account (Apple ID) | apple-admin@mptwork.com (shared mailbox) |
Apple Business administrator + the annual APNs push certificate |
| 2 | Apple Business organization | enrolled at business.apple.com |
Automated Device Enrollment + Apps & Books, linked to Intune |
| 3 | Managed Google Play account | IntuneGooglePlay@mptwork.com (Entra account with a mailbox) |
Android Enterprise binding for Intune |
Golden rule: all three must be dedicated, role-based, organization-owned accounts — never a personal Apple ID, personal Gmail, or a named employee who might leave. Store every credential in the team password manager.
Part 1 — Create the company Apple Account
- In the Microsoft 365 admin center, create a shared, role-based mailbox first, e.g.
apple-admin@mptwork.com, so the account is not tied to any individual and can receive Apple's mail. - Go to
https://account.apple.comand create a new Apple Account usingapple-admin@mptwork.com.- The email must not already be used for any other Apple service (iCloud, App Store, an existing Apple ID). If it is, choose a different dedicated address.
- Turn on two-factor authentication and set trusted phone number(s) the IT team controls (not a personal phone).
- Record the credentials in the team password manager. This single account will be used both to administer Apple Business (Part 2) and to create/renew the APNs certificate.
Part 2 — Enroll in Apple Business (formerly Apple Business Manager)
2.1 Gather the business identifier
- United States: have the organization's Federal Taxpayer Identification Number (EIN/TIN) ready.
- Other countries: confirm the required identifier; if a D-U-N-S number is needed, look it up (and request one free if absent) at
https://developer.apple.com/enroll/duns-lookup/— allow ~5 business days.
2.2 Sign up
- Go to
https://business.apple.comand choose Sign up now. - Enter:
- Full name — a legal human name of the person enrolling (not a job title like "IT Coordinator").
- Work email — the company Apple Account
apple-admin@mptwork.com. - Organization name (and optionally the website,
mptwork.com), and country/region.
- Enter the one-time codes Apple sends (first to email, then to phone) to confirm.
2.3 Verify the organization
- Sign in → Organization settings → Verify.
- Enter the business identifier (US: Federal TIN; elsewhere: D-U-N-S/country identifier).
- Enter a verification contact (name, email, role) Apple can call — typically the CEO, CTO, or CFO.
- Watch for the email "Your enrollment is in review." Allow mail from all
apple.comdomains and make sure the verification contact answers or returns Apple's call. - Verification takes multiple business days. If the organization isn't approved within the verification window, the organization and its data are deleted — respond to Apple promptly.
2.4 Immediately after approval
- Create at least one additional Administrator. Before a second admin exists, a lost password can only be recovered via
iforgot.apple.com— a single point of failure. - (Optional) Federate Apple Business with Microsoft Entra ID so Managed Apple Accounts use
mptwork.comsign-in.
2.5 Link Apple Business and the APNs certificate to Intune
- APNs (Apple MDM push) certificate: Intune → Devices → Enrollment → Apple → Apple MDM push certificate. Download the CSR, sign in to the Apple Push Certificates Portal with the company Apple Account, upload the CSR, download the certificate, and upload it back into Intune. Record the Apple Account and the annual expiry — renew every year with the same account.
- Automated Device Enrollment (ADE): download the public key from Intune, create an MDM server in Apple Business and upload the key, then upload the resulting token back into Intune. Assign device serial numbers to the Intune MDM server.
- Apps & Books (VPP) token: download from Apple Business and upload to Intune to license App Store apps.
(Detailed Intune-side steps are in the device-management companion SOP.)
Part 3 — Create the corporate Google account for Managed Google Play
Managed Google Play is required for every Android Enterprise mode in Intune (personally-owned work profile, corporate-owned work profile, fully managed, dedicated).
3.1 Prepare the account
- In the Microsoft 365 / Entra admin center, create a dedicated Entra account with an active mailbox, e.g.
IntuneGooglePlay@mptwork.com.- It must have a mailbox (Google sends a validation message).
- Do not use a personal Gmail, a named user who may leave, or an existing admin account used for other things.
- Assign it the Intune Administrator role (or a custom role with organization read/update permissions).
- Consumer-account pre-check: make sure
IntuneGooglePlay@mptwork.comis not already tied to a consumer Google account. If it is, the connect step fails with "Email address is associated with an existing consumer account." Resolve it first by signing in athttps://myaccount.google.comand deleting that consumer Google account, then continue.
3.2 Connect Intune to Managed Google Play
- Sign in to the Intune admin center → Devices → Enrollment → Android → Managed Google Play.
- Check "I agree" to grant Microsoft permission to send user/device info to Google, then Launch Google / Connect now.
- On Create admin account, enter the corporate email
IntuneGooglePlay@mptwork.com, then choose Sign in with Microsoft and authenticate. - Accept the requested permissions.
- On Tell us about you, enter the details; set Organization name = MPT Work; the EMM provider shows Microsoft Intune.
- Add the Android Enterprise subscription (it is free), then Agree and continue → Allow and create account.
- You are redirected back to Intune; the connection shows a green check with the account and registration date. The four Android Enterprise enrollment modes are now available.
3.3 After connecting
- In the Google admin console, add a second owner/admin — Google recommends at least two owners for redundancy.
- Important constraint: you cannot migrate or change the Managed Google Play account later without unenrolling all Android Enterprise devices. Choose this account deliberately.
Outcome and ongoing care
At the end you have: a dedicated company Apple Account, a verified Apple Business organization linked to Intune (APNs + ADE + VPP), and a Managed Google Play binding — enabling Intune to manage Apple and Android devices.
| Item | Cadence | Action |
|---|---|---|
| APNs certificate | Annually | Renew with the same company Apple Account before expiry, or all Apple devices fall out of management |
| Apple Business / VPP / ADE tokens | Annually | Renew before expiry |
| Account ownership | Ongoing | Keep the shared mailboxes and credentials in the password manager; maintain ≥2 admins on each side |
Notes and caveats
- The April 2026 Apple Business rename and US TIN change mean older walkthroughs may not match the current portal — follow
business.apple.comand Apple's current guide. - Apple Business and Managed Google Play are free; Intune (your MDM) is the licensed component.
- Verify current steps against Apple and Microsoft documentation, as both flows change periodically.