Domain not verified in both consoles
The wizard blocks with no useful error. Verify in Entra first, then in Apple
Business. Both TXT records have to land before the Federate button becomes
meaningful.
Admin accounts on the federated domain
Administrators and People Managers can’t use federated sign-in. Create a
break-glass admin on a non-federated domain (a
@yourcompany.onmicrosoft.com Managed Apple Account is the usual
move).
SCIM provisioning silently stalled
Always open Entra’s Provisioning logs. A failing mapping shows
“provisioned 0, skipped N” without raising an alert. Remove any
custom attribute mappings you added.
SCIM token expiry
SCIM tokens expire. Apple emails admins 60 days out. Renew via Apple
Business → Directory Sync → Edit, then paste the new token into
the Entra app. If you skipped SCIM and picked OIDC sync, this risk disappears.
Tenant reused across two Apple Business orgs
Not supported. One Entra tenant = one Apple Business org over OIDC. MSPs
managing multiple Apple Business tenants need one Entra tenant per org.
Sign in with Apple breakage
Third-party apps that used the old personal Apple ID email for Sign in with
Apple don’t auto-transfer after rename. Warn users during the 60-day
window so they update relationships themselves.