So not sure if this is related but, I am testing our Apple Business Manager Federated Authentication with Microsoft on my test tenant. I did this a couple of months ago.
How that process went in the past:
- Connected ABM and Microsoft with my microsoft account
- An Enterprise App called "Apple Business Manager SAML" was created
- Was able to add users and groups to provision
Now, I did this recently and no SAML was created. Instead, a new Apple Business Manager app was generated that utilizes Open ID Connect (OIDC). I am not able to provision specific users or groups. It now syncs everything in my domain (service accounts, etc).
So in your case, it might not be syncing because Apple is now wanting us to use the OIDC method?
Apple changed some stuff recently. I called support and they did confirm something was modified. Even this article shows a timestamp of June 2024 when it was last edited. I do not remember seeing any OIDC stuff before.
So not sure if:
Apple did something wrong or if Microsoft implemented the Enterprise app in their catalog wrong.