Forum Discussion
VPP Apps Not Installing via Intune – Error 0x87D127DB Despite Valid Configuration
- Jun 18, 2025
Hi everyone,
I wanted to share my recent experience that might be helpful to others dealing with firewall configurations and Apple service integrations.
At the request of management, I implemented a policy to block streaming services via our firewall. To do this efficiently, I used the vendor’s built-in web filtering categories, as manually blocking every streaming provider is practically unmanageable.
Unfortunately, I lost sight of this change over time. What I didn’t realize—and what isn’t clearly documented by the vendor—is that the selected category also blocks essential Apple services. Specifically, it interferes with the communication between Apple Business Manager (ABM) and Microsoft Intune. This behavior is reproducible and was the root cause of the issues we encountered.
To be clear: The issue was not caused by Apple Business Manager or Intune, but solely by the firewall configuration.
I’m now working on a more targeted approach to block streaming content without disrupting ABM–Intune connectivity.
Best regards,
MSThomK
Hi J-Wr1ght
Unfortunately, there is still no solution to this issue. Apple Support recommended the following workaround until the problem is resolved:
You can install VPP apps using Apple Configurator, bypassing Intune. I tried this approach. I was able to see the device in Apple Configurator, select one of our VPP apps, and initiate the installation. The app was downloaded, but the installation failed with an error message.
I have also reported this to the Microsoft support
How are things looking on your end?
Hi MSThomK
Strangely for me it has resolved itself in the last couple of days. I didn't get chance to test due to exam setup but now it is working. I submitted a service outage but Microsoft said there wasn't a problem. I then submitted a support ticket (it started working at this point) and the engineer wasn't sure what would have caused the issue and why it would do this. It all points to issues between two competing services where once makes a change and the other has to react.
Will keep an eye on it and see what happens.
Thanks,
James