
UpTrajectory Review
A recent report highlights significant security vulnerabilities in Apple's Business Manager authentication system, particularly affecting IT administrators. While Apple is known for its secure platforms, the inability for admin accounts to use federated authentication poses a serious risk, exposing critical accounts to potential exploitation.
For small business operators, this issue is particularly concerning as it underscores the importance of robust authentication measures. Relying on SMS-based two-factor authentication for admin accounts is outdated and risky, given the prevalence of SIM swapping and phishing attacks. Businesses should consider alternative authentication methods, such as hardware tokens or app-based authenticators, to enhance security. This situation serves as a reminder that even trusted platforms can have vulnerabilities that need addressing.
“It means the key accounts that manage protection for sometimes thousands of devices are still only protected by a six-digit SMS code.” — Computerworld
Takeaway: Evaluate your authentication methods and consider moving away from SMS-based two-factor authentication for critical accounts.
Excerpt from the original — Computerworld
Apple’s platforms are secure by design, but when it comes to authentication, the company seems to be protecting employees more than it protects IT admins. It’s an attack vector just waiting to be exploited — if it hasn’t been already.
As noted first by Six Colors, the problem is that administrator and People Manager accounts on Apple Business Manager (ABM) can’t sign in using federated authentication, even though they manage the federation process for everyone else.
What are the implications?
What this means in practice is that when admins engage with the authentication process, they need to do so using non-federated Apple Account sign-in with Apple’s two‑factor authentication (typically via a trusted device or trusted phone number using SMS/voice). That’s weird; it means the key accounts that manage protection for sometimes thousands of devices are still only protected by a …