We manage around 30 company-owned iPhones through Apple Business Manager and Intune. Most employees do not need to install apps, but some may need to download an app unexpectedly while working remotely or outside normal helpdesk hours. These apps can include parking, venue, restaurant, or other services where an app may be the only practical option.
The devices were originally set up with a mixture of personal Apple Accounts, some using company email addresses. Because features such as Face ID and Stolen Device Protection are enabled, changing or recovering some accounts has been difficult. We now want to avoid using business email addresses for personal accounts and need a workable approach for occasional App Store purchases or downloads.
Apple advised using a separate personal iCloud account signed in only to the App Store. However, I am concerned about employees creating accounts with company-managed phone numbers, taking those accounts with them when they leave, and preventing future employees from registering accounts with the same number. I have also encountered messages saying that a phone number is already associated with another Apple Account.
What is the recommended way to handle this while keeping the phones managed? Can users sign into only the App Store with a personal account, and how do phone-number associations, employee departures, Activation Lock, and account recovery work in this setup?
4 Answers
The usual solution is to let the employee use a personal Apple Account only for the App Store, while the device remains managed and the primary account or enrollment stays under your organization. The App Store account can be different from the account used for iCloud and device services. If personal use is allowed, employees should create those accounts with their own personal details rather than a company email address.
A mobile number is not generally exclusive to a single Apple Account. It can be associated with multiple accounts, although Apple may still reject a particular registration or require additional verification depending on the account history and region. In practice, employees should retain ownership of their personal accounts and use personal recovery details, so the organization is not responsible for recovering them after the employee leaves.
Make sure Activation Lock is handled separately from App Store access. In Intune, review the supervised-device setting that allows Activation Lock. With the right configuration, you can retain an Activation Lock bypass code or remove Activation Lock through Apple Business Manager when a device is wiped or reassigned. Save any bypass information before erasing or removing the device, and test the process before relying on it.
This is important because a personal App Store account does not have to prevent the organization from managing the device or recovering it when ownership changes.
If an app is essential for work, distributing it through Apple Business Manager and Intune is more reliable than depending on employees to create personal accounts. For genuinely optional or unpredictable apps, a personal App Store account may be the only practical route, but the company should document that the account belongs to the employee and must not use the company domain or business recovery information.

That separation is also my understanding: the phone can remain enrolled in management while the App Store uses a different Apple Account.