Home

Deploying iOS VPP Apps to Users?

%3CLINGO-SUB%20id%3D%22lingo-sub-449929%22%20slang%3D%22en-US%22%3EDeploying%20iOS%20VPP%20Apps%20to%20Users%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-449929%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20just%20received%20our%20first%20batch%20auf%20DEP%20enrolled%20iOS%20devices.%20Until%20now%20we%20had%20to%20let%20the%20user%20manually%20enroll%20the%20company%20issued%20iOS%20devices%20and%20also%20create%20their%20own%20AppleID%20is%20with%20the%20business%20email.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20we%20wanted%20to%20achieve%20is%20that%20make%20the%20enrollment%20process%20as%20easy%20as%20possible%20and%20also%20eliminate%20the%20need%20for%20an%20AppleID.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI've%20configured%20the%20Enrollment%20Profile%20with%20a%20VPP%20Token%20and%20can%20confirm%20that%20all%20this%20works.%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20I'm%20having%20trouble%20is%20deploying%20specific%20apps%20to%20specific%20subset%20of%20users.%20Previously%20I%20just%20targeted%20a%20user%20group.%26nbsp%3B%3C%2FP%3E%3CP%3EFrom%20what%20I%20understand%20is%2C%20that%20I%20could%20do%20this%20again%2C%20but%20then%20the%20user%20would%20have%20to%20provide%20an%20Apple%20ID%20again%20-%20at%20least%20I%20get%20that%20prompt%20in%20my%20test%20scenario.%3C%2FP%3E%3CP%3EI%20therefore%20created%20a%20Azure%20AD%20Device%20Groups%20for%20targeting%20my%20app%20deployments.%20This%20seems%20to%20work%2C%20but%20I%20have%20a%20couple%20of%20issues%20or%20questions%20about%20that%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EWhen%20I%20don't%20want%20any%20Apple%20ID%20prompts%2C%20I%20have%20to%20use%20device%20licensing%20when%20I%20assigning%20VPP%20apps%2C%20correct%3F%3C%2FLI%3E%3CLI%3EI%20have%20noticed%2C%20that%20when%20I%20assign%20an%20app%20with%20device%20licensing%20to%20a%20user%20security%20group%2C%20that%20the%20app%20does%20not%20get%20deployed%20to%20the%20device.%20Is%20this%20expected%20behavior%3F%3C%2FLI%3E%3CLI%3EI%20have%20noticed%20that%20I%20can%20deploy%20apps%20with%20device%20licensing%20as%20%22available%22%20but%20the%20app%20does%20not%20appear%20in%20the%20iOS%20company%20portal.%20Users%20therefore%20cannot%20install%20them.%20Is%20this%20expected%20behavior%3F%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLI%3E%3CLI%3EBiggest%20question%20right%20now%3A%20How%20do%20I%20assign%20a%20specific%20app%2C%20to%20multiple%20specific%20users%20(more%20specifically%20their%20devices)%3F%3CUL%3E%3CLI%3EThe%20documentation%20mentions%20Azure%20AD%20Dynamic%20Device%20Groups%20based%20on%20the%20Device%20Category%3CUL%3E%3CLI%3Ethose%20users%20don't%20share%20a%20device%20category%3C%2FLI%3E%3C%2FUL%3E%3C%2FLI%3E%3CLI%3Edeploying%20to%20user%20groups%20doesn't%20work%20(see%20question%20above)%3C%2FLI%3E%3CLI%3EI%20would%20create%20an%20Assigned%20AAD%20Group%20with%20devices%2C%20but%20this%20leads%20to%20another%20problem%3A%3CUL%3E%3CLI%3Eall%20DEP%20enrolled%20iPhones%20are%20named%20%22iPhone%22.%20When%20you%20try%20to%20add%20devices%20as%20members%20to%20a%20group%2C%20I%20cannot%20differentiate%20between%20any%20iPhone%20(i%20would%20need%20the%20username%2Fserialnumber%20columns%20for%20that).%3C%2FLI%3E%3CLI%3EThere%20is%20also%20no%20reverse%20way%2C%20by%20going%20to%20Intune%20%26gt%3B%20Devices%20and%20searching%20for%20it%20and%20then%20adding%20to%20a%20group%2C%20as%20there%20is%20no%20Action%20%22Add%20to%20group%22%20or%20something%20similar%3C%2FLI%3E%3CLI%3EI'm%20currently%20trying%20to%20rename%20the%20Intune%20Devices%20by%20adding%20our%20inventory%20label%2C%20but%20this%20process%20is%20manual%2C%20and%20sometimes%20fails%20with%20errors%20and%20I%20have%20no%20idea%20why.%3C%2FLI%3E%3C%2FUL%3E%3C%2FLI%3E%3C%2FUL%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%20some%20minor%20issue%20I%20have%20is%2C%20that%20I%20added%20my%20device%20manually%20to%20a%20device%20group%20after%20creating%20the%20device%20group%20but%20an%20AAD%20dynamic%20group%20based%20on%20this%20category%20is%20not%20picking%20up%20my%20device%20and%20I%20have%20no%20idea%20why.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20help%20is%20appreciated%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-449929%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-453727%22%20slang%3D%22en-US%22%3ERe%3A%20Deploying%20iOS%20VPP%20Apps%20to%20Users%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-453727%22%20slang%3D%22en-US%22%3E%3CUL%3E%3CLI%3E%3CFONT%3EWhen%20I%20don't%20want%20any%20Apple%20ID%20prompts%2C%20I%20have%20to%20use%20device%20licensing%20when%20I%20assigning%20VPP%20apps%2C%20correct%3F%3C%2FFONT%3E%3CUL%3E%3CLI%3E%3CSTRONG%3E%3CFONT%3E%26nbsp%3BCorrect%2C%20since%20targeting%20a%20license%20to%20a%20user%20requires%20an%20Apple%20ID%3C%2FFONT%3E%3C%2FSTRONG%3E%3C%2FLI%3E%3C%2FUL%3E%3C%2FLI%3E%3CLI%3E%3CFONT%3EI%20have%20noticed%2C%20that%20when%20I%20assign%20an%20app%20with%20device%20licensing%20to%20a%20user%20security%20group%2C%20that%20the%20app%20does%20not%20get%20deployed%20to%20the%20device.%20Is%20this%20expected%20behavior%3F%3C%2FFONT%3E%3CUL%3E%3CLI%3E%3CSTRONG%3E%3CFONT%3ENo%2C%20the%20app%20should%20get%20pushed%20to%20the%20device%20when%20targeting%20a%20user%20group%20with%20type%20Security.%3C%2FFONT%3E%3C%2FSTRONG%3E%3C%2FLI%3E%3C%2FUL%3E%3C%2FLI%3E%3CLI%3E%3CFONT%3EI%20have%20noticed%20that%20I%20can%20deploy%20apps%20with%20device%20licensing%20as%20%22available%22%20but%20the%20app%20does%20not%20appear%20in%20the%20iOS%20company%20portal.%20Users%20therefore%20cannot%20install%20them.%20Is%20this%20expected%20behavior%3C%2FFONT%3E%3CFONT%3E%3F%3C%2FFONT%3E%3CUL%3E%3CLI%3E%3CSTRONG%3E%3CFONT%3ENo%2C%20the%20app%20should%20be%20listed%20in%20the%20company%20portal%20application%20for%20the%20user.%20Sometimes%20it%20can%20take%20time%20before%20the%20app%20appears%2C%20how%20long%20have%20you%20waited%3F%3C%2FFONT%3E%3C%2FSTRONG%3E%3C%2FLI%3E%3C%2FUL%3E%3C%2FLI%3E%3CLI%3E%3CFONT%3EBiggest%20question%20right%20now%3A%20How%20do%20I%20assign%20a%20specific%20app%2C%20to%20multiple%20specific%20users%20(more%20specifically%20their%20devices)%3F%3CBR%20%2F%3EThe%20documentation%20mentions%20Azure%20AD%20Dynamic%20Device%20Groups%20based%20on%20the%20Device%20Category%3CBR%20%2F%3Ethose%20users%20don't%20share%20a%20device%20category%3CBR%20%2F%3Edeploying%20to%20user%20groups%20doesn't%20work%20(see%20question%20above)%3C%2FFONT%3E%3CUL%3E%3CLI%3E%3CFONT%3E%3CSTRONG%3EAssigning%20to%20a%20user%20group%20instead%20of%20device%20is%20easier%20and%20something%20I%20would%20reccomend.%20It%20seems%20like%20you%20have%20config%20issues%20in%20your%20environment.%3CBR%20%2F%3EIs%20your%20APNs%20certificate%20active%3F%3CBR%20%2F%3EIs%20the%20device%20compliant%3F%3C%2FSTRONG%3E%20%3C%2FFONT%3E%3C%2FLI%3E%3CLI%3E%3CFONT%3E%3CSTRONG%3EAre%20you%20able%20to%20send%20any%20other%20commands%20to%20the%20device%2C%20remote%20lock%20etc%3F%3C%2FSTRONG%3E%20%3C%2FFONT%3E%3CSTRONG%3E%3CFONT%3EIf%20the%20device%20is%20not%20supervised%20you%20will%20get%20a%20notification%20to%20which%20the%20user%20has%20to%20respond%20for%20the%20application%20to%20be%20installed.%20If%20supervised%2C%20it%20should%20be%20installed%20silently.%3C%2FFONT%3E%3C%2FSTRONG%3E%3C%2FLI%3E%3CLI%3E%3CSTRONG%3E%3CFONT%3EHow%20have%20you%20setup%20the%20groups%20to%20which%20you%20are%20assigning%20apps%3F%3C%2FFONT%3E%3C%2FSTRONG%3E%3C%2FLI%3E%3C%2FUL%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-486911%22%20slang%3D%22en-US%22%3ERe%3A%20Deploying%20iOS%20VPP%20Apps%20to%20Users%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-486911%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F310475%22%20target%3D%22_blank%22%3E%40almennn%3C%2FA%3E%26nbsp%3BHi%2C%20I%20think%20you%20possibly%20crossed%20over%20to%20user%20licensing%20after%20question%20number%201%3F%3C%2FP%3E%3CP%3EWe've%20previously%20used%20personal%20Apple%20IDs%20with%20User%20Licensing.%20But%20now%20that%20we%20have%20DEP-enabled%20devices%20the%20goal%20is%20that%20the%20user%20does%20not%20require%20an%20Apple%20ID%20at%20all.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlease%20verify%3A%3C%2FP%3E%3CUL%3E%3CLI%3EDEP%20(or%20Apple%20Configurator)%20enrolled%20iOS%20Device%3C%2FLI%3E%3CLI%3ESecurity%20Group%20has%20Users%2C%20not%20Devices%20in%20them%3C%2FLI%3E%3CLI%3EApp%20is%20assigned%20as%20available%20to%20that%20User%20Security%20Group%3C%2FLI%3E%3CLI%3EUser%20can%20install%20the%20available%20app%20manually%20from%20the%20Company%20Portal%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERight%20now%20I%20don't%20see%20any%20app%20at%20all%20in%20the%20Company%20Portal%20App.%20It%20say%20%22no%20apps%20available%22%20and%20there%20is%20a%20%22Company%20Portal%20App%22%20Text%20button%20below.%20When%20I%20click%20that%20link%20and%20log%20in%2C%20funnily%20enough%2C%20I%20see%20the%20app%20as%20%22available%22.%20When%20I%20want%20to%20install%20it%20from%20the%20company%20portal%20website%2C%20I%20have%20to%20confirm%20that%20the%20iOS%20device%20is%20company%20managed%2C%20even%20though%20it%20already%20is%20listed%20as%20Corporate%20Owned.%20After%20that%20I%20can%20click%20Install%20and%20the%20app%20even%20installs%20in%20the%20background.%20It%20is%20still%20not%20listed%20within%20the%20Company%20Portal%20App%20though%2C%20even%20after%20it%20has%20installed%20successfully.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESee%20those%20screenshots.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20462px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F110646iA33D374B61EAB745%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Image.jpg%22%20title%3D%22Image.jpg%22%20%2F%3E%3C%2FSPAN%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20462px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F110647i22C6CC65A6F2937E%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Image-1.jpg%22%20title%3D%22Image-1.jpg%22%20%2F%3E%3C%2FSPAN%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20462px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F110649i2E77CF82FB3A798C%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Image-2.jpg%22%20title%3D%22Image-2.jpg%22%20%2F%3E%3C%2FSPAN%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20462px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F110648i465D7701811EA3A0%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Image-3.jpg%22%20title%3D%22Image-3.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-487721%22%20slang%3D%22en-US%22%3ERe%3A%20Deploying%20iOS%20VPP%20Apps%20to%20Users%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-487721%22%20slang%3D%22en-US%22%3ESo%20I've%20done%20some%20further%20testing%2C%20and%20it%20seems%20that%20%22available%22%20(device%20licensed)%20apps%20do%20show%20on%20on%20the%20company%20portal%20website%2C%20but%20not%20directly%20in%20the%20app.%20Any%20idea%20why%3F%3C%2FLINGO-BODY%3E
Ivan Unger
Valued Contributor

Hi,

 

We have just received our first batch auf DEP enrolled iOS devices. Until now we had to let the user manually enroll the company issued iOS devices and also create their own AppleID is with the business email.

 

What we wanted to achieve is that make the enrollment process as easy as possible and also eliminate the need for an AppleID. 

 

I've configured the Enrollment Profile with a VPP Token and can confirm that all this works. 

What I'm having trouble is deploying specific apps to specific subset of users. Previously I just targeted a user group. 

From what I understand is, that I could do this again, but then the user would have to provide an Apple ID again - at least I get that prompt in my test scenario.

I therefore created a Azure AD Device Groups for targeting my app deployments. This seems to work, but I have a couple of issues or questions about that:

 

  • When I don't want any Apple ID prompts, I have to use device licensing when I assigning VPP apps, correct?
  • I have noticed, that when I assign an app with device licensing to a user security group, that the app does not get deployed to the device. Is this expected behavior?
  • I have noticed that I can deploy apps with device licensing as "available" but the app does not appear in the iOS company portal. Users therefore cannot install them. Is this expected behavior?

  • Biggest question right now: How do I assign a specific app, to multiple specific users (more specifically their devices)?
    • The documentation mentions Azure AD Dynamic Device Groups based on the Device Category
      • those users don't share a device category
    • deploying to user groups doesn't work (see question above)
    • I would create an Assigned AAD Group with devices, but this leads to another problem:
      • all DEP enrolled iPhones are named "iPhone". When you try to add devices as members to a group, I cannot differentiate between any iPhone (i would need the username/serialnumber columns for that).
      • There is also no reverse way, by going to Intune > Devices and searching for it and then adding to a group, as there is no Action "Add to group" or something similar
      • I'm currently trying to rename the Intune Devices by adding our inventory label, but this process is manual, and sometimes fails with errors and I have no idea why.

 

Also some minor issue I have is, that I added my device manually to a device group after creating the device group but an AAD dynamic group based on this category is not picking up my device and I have no idea why.

 

Any help is appreciated

3 Replies
  • When I don't want any Apple ID prompts, I have to use device licensing when I assigning VPP apps, correct?
    •  Correct, since targeting a license to a user requires an Apple ID
  • I have noticed, that when I assign an app with device licensing to a user security group, that the app does not get deployed to the device. Is this expected behavior?
    • No, the app should get pushed to the device when targeting a user group with type Security.
  • I have noticed that I can deploy apps with device licensing as "available" but the app does not appear in the iOS company portal. Users therefore cannot install them. Is this expected behavior?
    • No, the app should be listed in the company portal application for the user. Sometimes it can take time before the app appears, how long have you waited?
  • Biggest question right now: How do I assign a specific app, to multiple specific users (more specifically their devices)?
    The documentation mentions Azure AD Dynamic Device Groups based on the Device Category
    those users don't share a device category
    deploying to user groups doesn't work (see question above)
    • Assigning to a user group instead of device is easier and something I would reccomend. It seems like you have config issues in your environment.
      Is your APNs certificate active?
      Is the device compliant?
    • Are you able to send any other commands to the device, remote lock etc? If the device is not supervised you will get a notification to which the user has to respond for the application to be installed. If supervised, it should be installed silently.
    • How have you setup the groups to which you are assigning apps?

 

@almennn Hi, I think you possibly crossed over to user licensing after question number 1?

We've previously used personal Apple IDs with User Licensing. But now that we have DEP-enabled devices the goal is that the user does not require an Apple ID at all.

 

Please verify:

  • DEP (or Apple Configurator) enrolled iOS Device
  • Security Group has Users, not Devices in them
  • App is assigned as available to that User Security Group
  • User can install the available app manually from the Company Portal

 

Right now I don't see any app at all in the Company Portal App. It say "no apps available" and there is a "Company Portal App" Text button below. When I click that link and log in, funnily enough, I see the app as "available". When I want to install it from the company portal website, I have to confirm that the iOS device is company managed, even though it already is listed as Corporate Owned. After that I can click Install and the app even installs in the background. It is still not listed within the Company Portal App though, even after it has installed successfully. 

 

See those screenshots.

 

Image.jpgImage-1.jpgImage-2.jpgImage-3.jpg

 

So I've done some further testing, and it seems that "available" (device licensed) apps do show on on the company portal website, but not directly in the app. Any idea why?
Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
38 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies