Third-party app access blocks consent
If Google Admin → Security → API controls is set to “allow users
to access only trusted apps,” the Apple OAuth client must be on the trusted
list. Otherwise consent appears to succeed but nothing federates.
OU scope gaps
Directory sync only pulls from the OUs you tick in Apple Business’s scope
picker. Users in /Contractors or /Service Accounts that
weren’t selected will not become Managed Apple Accounts and cannot sign in.
Admin accounts on the federated domain
Apple Business Administrators and People Managers cannot use federated sign-in.
Keep a break-glass admin on a non-federated domain or a throwaway
@yourcompany.onmicrosoft.com-style Managed Apple Account.
Hardware-key 2SV and WebAuthn
If the Super Admin enforces hardware-key-only 2‑Step Verification, make
sure the browser supports WebAuthn during consent. Some kiosk or locked-down
browsers fail silently here.
Switching from a prior IdP
If the domain was federated to Entra or a Custom IdP, existing Managed Apple
Account users must re-authenticate — cached IdP passwords won’t work.
Disconnect the previous IdP first, let any conflict work finish, then federate to
Google.
Apple Business migration window
During the April 2026 rollout to the Apple Business UI, the domain management
pane is briefly locked on some tenants. If the Federate button is greyed out for
no reason, check the Apple Business status page and retry the next day.