Back to blog

Shared iPad: prepare Authenticated Guest Mode for enterprise

Article created September 25, 2026 · Apple documentation published September 17, 2026 and reviewed September 25, 2026 · Topic: Shared iPad, identity, MDM, and security

Apple says Authenticated Guest Mode will become available on Shared iPad in a later iPadOS 27 update. The announcement opens an authenticated shared-use model for retail, healthcare, manufacturing, and field services, but Apple has not named the exact release. IT teams should prepare their architecture and tests without treating the feature as production-ready today.

1. What Apple announced — and what remains unconfirmed

In its Shared iPad guide updated September 17, 2026, Apple says the mode will arrive “later this year” in an iPadOS 27 update. When configured with Temporary Session Only, it will provide a temporary session after authentication with a Managed Apple Account, using native authentication or federation with an identity provider.

Apple also announces automatic SSO in supported apps, no need to configure user storage quotas, and removal of local data, the session passcode, and the Managed Apple Account at sign-out. The documentation still provides no exact version or date. These guarantees must be verified with the apps and MDM actually in use.

2. Separate managed accounts, temporary sessions, and authenticated guests

Shared iPad already supports persistent sessions with a Managed Apple Account and anonymous temporary sessions. The future mode combines managed-account authentication with the local cleanup of a temporary session. If a passcode policy applies, the user creates a session-specific passcode subject to its complexity requirements, which unlocks that active session.

Each use case must therefore state whether users need to recover data across sessions: this new mode is specifically designed for a non-persistent session. Teams must also verify which business apps support the announced SSO behavior. Our guide to Managed Apple Accounts helps frame the governance of that identity.

3. What does this announcement change for a Belgian or French organization?

For an SME, the potential benefit is sharing iPads without assigning a named device to every employee. For a mid-market organization, large enterprise, or public body, the topic affects counter, care, production, and logistics devices where the user must be identified while limiting data left locally after a shift.

In Belgium and France, the pilot should involve IT, security, and data-protection owners. Authentication alone does not prove that local traces are removed correctly, logging is proportionate, or apps isolate their data. Support notices and procedures should also be available in the languages actually used at each site.

4. Underside analysis: qualify an entire session

The mode’s value will be measured across the full journey: wake, network access, authentication, MDM configuration delivery, business app launch, sign-out, and local-data handling. A test limited to the sign-in screen would miss the costliest risks: preparation delays, a previous user’s cache, or an undocumented network dependency.

Underside recommends preparing cohorts by role and site. Apple Business Manager or Apple School Manager associates devices with the organization, Automated Device Enrollment and MDM apply supervision and policies, and the network must work before any user signs in. Exact support from Jamf or another MDM must be confirmed in its documentation when the feature ships.

5. Preparation plan before availability

Objective: turn the announcement into a verifiable use case without confusing authentication, data persistence, and actual feature availability.

Prepare your shared iPads

Official Apple source: Shared iPad overview, published September 17, 2026.