I've heard multiple times directly from Apple employees that there is no way to login to iCloud on your work machine using a company-controlled account. Many people create new Apple ID's which they only use while working there, but others just use their personal iCloud accounts. You are, of course, not supposed to store company data in iCloud. But thanks to Apple's own efforts, it's difficult to use a Mac without being logged into iCloud (for example if you want to use the App store), and some data can easily spill into the iCloud account.
If accurate, it is of course patently absurd that Apple has left this an unsolved problem.
I have used a Macbook at work for 5 years without signing into any iCloud account ever.
Yes, that's correct - an Apple account is tied to a person. A person can have multiple Apple accounts, if they wish. But there is no such thing as an organizationally controlled Apple account.
Yes this seems incoherent and incompatible for a company that supposedly care about their trade secrets.
There is a solution though. I don't like it, but we use MDM to disable iCloud file sync, scan network communication and such.
You can log into your personal account and have iCloud file sync disabled. I mean what does that prevent that you couldnt do by some other means? I could also just use a browser to drag and drop anything to my personal google drive. Or use a usb stick.
I don’t understand people that create separate Apple accounts for work.
I’ve always used my personal account on corp laptops, including MFAANG. It’s awesome being able to use side car on my personal machines, hand-off on my AirPods, or screen mirroring to my Apple TV during conference calls. What are you gaining from isolating your account? Why even bother making a fake account at all?