AKAuthenticationError −7027 when using Sign in with Apple on iOS (Managed Apple ID / Shared iPad environment)

We are working on a PoC iOS App to use "Sign in with Apple" on iOS. The app needs to authenticate the current user on MDM managed corporate iPads (with Shared iPad enabled) and each user having a Managed Apple ID (created in Apple Business Manager). We have started with Apple's example app: https://developer.apple.com/documentation/authenticationservices/implementing-user-authentication-with-sign-in-with-apple When we run it on a normal iPad (without MDM supervision) it works fine. When we run the same code on a managed iPad with Shared iPad enabled and Managed Apple ID's the app errors out when a user taps the "Sign in with Apple" button. A User-facing error message is displayed: “Your Apple Account cannot be used to create accounts for other apps.” And when we run the app from Xcode we see the following logs:

Authorization failed: Error Domain=AKAuthenticationError Code=-7027 "(null)" UserInfo={AKClientBundleID=com.sampleapp.test2} LaunchServices: store (null) or url (null) was nil: Error Domain=NSOSStatusErrorDomain Code=-54 "process may not map database" UserInfo={NSDebugDescription=process may not map database, _LSLine=72, _LSFunction=_LSServer_GetServerStoreForConnectionWithCompletionHandler} Attempt to map database failed: permission was denied. This attempt will not be retried. Failed to initialize client context with error Error Domain=NSOSStatusErrorDomain Code=-54 "process may not map database" UserInfo={NSDebugDescription=process may not map database, _LSLine=72, _LSFunction=_LSServer_GetServerStoreForConnectionWithCompletionHandler} Failed to get application extension record: Error Domain=NSOSStatusErrorDomain Code=-54 "(null)" ASAuthorizationController credential request failed with error: Error Domain=com.apple.AuthenticationServices.AuthorizationError Code=1000 "(null)" Could not authenticate: The operation couldn’t be completed. (com.apple.AuthenticationServices.AuthorizationError error 1000.)

We have confirmed that in ABM "Sign in with Apple" feature is enabled with "Allowed apps": "All apps". We have also confirmed that the Managed AppleIDs created in ABM have no field to provide the birthday of the user and therefore ruling out age restrictions for "Sign in with Apple".

Is "Sign in with Apple" supported in MDM managed iPADs with Shared iPad enabled and managed AppleIDs?

If it is supported, do we know what other configurations we need to get it to work?

Do we know why "Sign in with Apple" would error out with Authorization failed: Error Domain=AKAuthenticationError Code=-7027 "(null)" UserInfo={AKClientBundleID=com.sampleapp.test2} LaunchServices: store (null) or url (null) was nil: Error Domain=NSOSStatusErrorDomain Code=-54 "process may not map database" UserInfo={NSDebugDescription=process may not map database, _LSLine=72,

Environment: • iPadOS version: IPadOS Version 18.7 • Xcode version: Version 26.0 (17A324) • Device type: iPad Air 11-inch (M3) in Shared iPad mode • Account type: Managed Apple ID created in ABM enrolled with Intune MDM)

Thank you

Answered by DTS Engineer in 892023022

Hi @iOSD3v,

You wrote:

Is "Sign in with Apple" supported in MDM managed iPADs with Shared iPad enabled and managed AppleIDs? [...] If it is supported, do we know what other configurations we need to get it to work? [...] Do we know why "Sign in with Apple" would error out

No, Sign in with Apple is not supported and is explicitly excluded from Managed Apple Accounts. No MDM profile, payload, or restriction key can override this.

The ABM setting you mentioned ("Sign in with Apple" enabled for "All Apps") enabled the "Sign in with Apple at Work & School" flow, but that still requires additional configurations, and also is not supported on a Shared iPad.

Cheers,

Paris X Pinkney |  WWDR | DTS Engineer

Hi @iOSD3v,

You wrote:

Is "Sign in with Apple" supported in MDM managed iPADs with Shared iPad enabled and managed AppleIDs? [...] If it is supported, do we know what other configurations we need to get it to work? [...] Do we know why "Sign in with Apple" would error out

No, Sign in with Apple is not supported and is explicitly excluded from Managed Apple Accounts. No MDM profile, payload, or restriction key can override this.

The ABM setting you mentioned ("Sign in with Apple" enabled for "All Apps") enabled the "Sign in with Apple at Work & School" flow, but that still requires additional configurations, and also is not supported on a Shared iPad.

Cheers,

Paris X Pinkney |  WWDR | DTS Engineer

AKAuthenticationError −7027 when using Sign in with Apple on iOS (Managed Apple ID / Shared iPad environment)
 
 
Q