SOP — Provision a Company Apple Account, Apple Business (ABM), and a Corporate Google Account for Managed Google Play

Version 1.0
Date 2026-06-22
Tenant context mptwork.com (mptwork.onmicrosoft.com)
Purpose Create the three organization accounts that Intune needs to manage Apple and Android devices
Companion SOP Device management — sop-manage-devices-intune-mptwork.md
Recency note (June 2026): On April 14, 2026, Apple Business Manager became "Apple Business" (it now combines the old Apple Business Manager, Apple Business Essentials, and Apple Business Connect) — still at business.apple.com. In the United States, the D-U-N-S number is no longer required for verification; Apple now uses the Federal Taxpayer Identification Number (EIN/TIN). Other countries use country-specific identifiers (a D-U-N-S number may still apply). Older guides will say "Apple Business Manager" and "D-U-N-S required" — the steps below reflect the current flow.

Accounts you will create

# Account Example Purpose
1 Company Apple Account (Apple ID) apple-admin@mptwork.com (shared mailbox) Apple Business administrator + the annual APNs push certificate
2 Apple Business organization enrolled at business.apple.com Automated Device Enrollment + Apps & Books, linked to Intune
3 Managed Google Play account IntuneGooglePlay@mptwork.com (Entra account with a mailbox) Android Enterprise binding for Intune
Golden rule: all three must be dedicated, role-based, organization-owned accounts — never a personal Apple ID, personal Gmail, or a named employee who might leave. Store every credential in the team password manager.

Part 1 — Create the company Apple Account

  1. In the Microsoft 365 admin center, create a shared, role-based mailbox first, e.g. apple-admin@mptwork.com, so the account is not tied to any individual and can receive Apple's mail.
  2. Go to https://account.apple.com and create a new Apple Account using apple-admin@mptwork.com.
    • The email must not already be used for any other Apple service (iCloud, App Store, an existing Apple ID). If it is, choose a different dedicated address.
  3. Turn on two-factor authentication and set trusted phone number(s) the IT team controls (not a personal phone).
  4. Record the credentials in the team password manager. This single account will be used both to administer Apple Business (Part 2) and to create/renew the APNs certificate.

Part 2 — Enroll in Apple Business (formerly Apple Business Manager)

2.1 Gather the business identifier

  • United States: have the organization's Federal Taxpayer Identification Number (EIN/TIN) ready.
  • Other countries: confirm the required identifier; if a D-U-N-S number is needed, look it up (and request one free if absent) at https://developer.apple.com/enroll/duns-lookup/ — allow ~5 business days.

2.2 Sign up

  1. Go to https://business.apple.com and choose Sign up now.
  2. Enter:
    • Full name — a legal human name of the person enrolling (not a job title like "IT Coordinator").
    • Work email — the company Apple Account apple-admin@mptwork.com.
    • Organization name (and optionally the website, mptwork.com), and country/region.
  3. Enter the one-time codes Apple sends (first to email, then to phone) to confirm.

2.3 Verify the organization

  1. Sign in → Organization settings → Verify.
  2. Enter the business identifier (US: Federal TIN; elsewhere: D-U-N-S/country identifier).
  3. Enter a verification contact (name, email, role) Apple can call — typically the CEO, CTO, or CFO.
  4. Watch for the email "Your enrollment is in review." Allow mail from all apple.com domains and make sure the verification contact answers or returns Apple's call.
  5. Verification takes multiple business days. If the organization isn't approved within the verification window, the organization and its data are deleted — respond to Apple promptly.

2.4 Immediately after approval

  1. Create at least one additional Administrator. Before a second admin exists, a lost password can only be recovered via iforgot.apple.com — a single point of failure.
  2. (Optional) Federate Apple Business with Microsoft Entra ID so Managed Apple Accounts use mptwork.com sign-in.
  1. APNs (Apple MDM push) certificate: Intune → Devices → Enrollment → Apple → Apple MDM push certificate. Download the CSR, sign in to the Apple Push Certificates Portal with the company Apple Account, upload the CSR, download the certificate, and upload it back into Intune. Record the Apple Account and the annual expiry — renew every year with the same account.
  2. Automated Device Enrollment (ADE): download the public key from Intune, create an MDM server in Apple Business and upload the key, then upload the resulting token back into Intune. Assign device serial numbers to the Intune MDM server.
  3. Apps & Books (VPP) token: download from Apple Business and upload to Intune to license App Store apps.

(Detailed Intune-side steps are in the device-management companion SOP.)


Part 3 — Create the corporate Google account for Managed Google Play

Managed Google Play is required for every Android Enterprise mode in Intune (personally-owned work profile, corporate-owned work profile, fully managed, dedicated).

3.1 Prepare the account

  1. In the Microsoft 365 / Entra admin center, create a dedicated Entra account with an active mailbox, e.g. IntuneGooglePlay@mptwork.com.
    • It must have a mailbox (Google sends a validation message).
    • Do not use a personal Gmail, a named user who may leave, or an existing admin account used for other things.
  2. Assign it the Intune Administrator role (or a custom role with organization read/update permissions).
  3. Consumer-account pre-check: make sure IntuneGooglePlay@mptwork.com is not already tied to a consumer Google account. If it is, the connect step fails with "Email address is associated with an existing consumer account." Resolve it first by signing in at https://myaccount.google.com and deleting that consumer Google account, then continue.

3.2 Connect Intune to Managed Google Play

  1. Sign in to the Intune admin center → Devices → Enrollment → Android → Managed Google Play.
  2. Check "I agree" to grant Microsoft permission to send user/device info to Google, then Launch Google / Connect now.
  3. On Create admin account, enter the corporate email IntuneGooglePlay@mptwork.com, then choose Sign in with Microsoft and authenticate.
  4. Accept the requested permissions.
  5. On Tell us about you, enter the details; set Organization name = MPT Work; the EMM provider shows Microsoft Intune.
  6. Add the Android Enterprise subscription (it is free), then Agree and continue → Allow and create account.
  7. You are redirected back to Intune; the connection shows a green check with the account and registration date. The four Android Enterprise enrollment modes are now available.

3.3 After connecting

  1. In the Google admin console, add a second owner/admin — Google recommends at least two owners for redundancy.
  2. Important constraint: you cannot migrate or change the Managed Google Play account later without unenrolling all Android Enterprise devices. Choose this account deliberately.

Outcome and ongoing care

At the end you have: a dedicated company Apple Account, a verified Apple Business organization linked to Intune (APNs + ADE + VPP), and a Managed Google Play binding — enabling Intune to manage Apple and Android devices.

Item Cadence Action
APNs certificate Annually Renew with the same company Apple Account before expiry, or all Apple devices fall out of management
Apple Business / VPP / ADE tokens Annually Renew before expiry
Account ownership Ongoing Keep the shared mailboxes and credentials in the password manager; maintain ≥2 admins on each side

Notes and caveats

  • The April 2026 Apple Business rename and US TIN change mean older walkthroughs may not match the current portal — follow business.apple.com and Apple's current guide.
  • Apple Business and Managed Google Play are free; Intune (your MDM) is the licensed component.
  • Verify current steps against Apple and Microsoft documentation, as both flows change periodically.

Read more

SOP — Create and Manage Microsoft Azure for Enterprise

Version 1.0 Date 2026-06-22 Domain mptwork.com Model Identity rooted in the existing Microsoft Entra tenant; hierarchy of Management Groups → Subscriptions → Resource Groups → Resources Consoles Azure portal portal.azure.com · Entra admin center entra.microsoft.com Companion SOPs M365/Entra — sop-subscribe-manage-m365-mptwork.md, sop-entra-id-authentication-sso-mptwork.md · Network/IPAM — enterprise-ipam-reference-architecture.md · AWS

By admin

SOP — Create and Manage a Google Cloud (GCP) Account

Version 1.0 Date 2026-06-22 Domain mptwork.com Model GCP Organization rooted in Cloud Identity / Google Workspace for mptwork.com; hierarchy of Folders → Projects; workforce access via Google Groups, optionally federated to Microsoft Entra Companion SOPs Google Workspace — sop-subscribe-manage-google-workspace-mptwork.md · Entra auth & SSO — sop-entra-id-authentication-sso-mptwork.md · Network/IPAM — enterprise-ipam-reference-architecture.md

By admin