How to connect Intune MDM connect to Apple Business Manager and Public Store

Contact Us

Contact Us

[contact-form-7 404 "Not Found"]

This guide explains how to use the Microsoft Intune MDM to Intune connect to Apple Business Managed Apps, as well as AppStore Public applications, and deploy both for your company employees.

Before you start with the Apple Business Manager, make sure that your company was provided with access to the enterprise app, as explained here

  1. Enroll the devices (Apple MDM Push certificate already set before)
  2. Choose Apple Environment on the left menu
  3. Choose Enrollment program tokens
  4. You will see the list of program tokens, if available
  5. Click + Add at the top left menu
  6. A new enrolment plan will open as seen below
  7. Accept the selection of the I agree checkbox to Grant permission and Add the program token:
  8. Download your public key
  9. Choose to use the Apple Business Manager
  10. This will open a new window of the Apple Business console
    In this window, choose to add MDM Server – by clicking on the Add on the right
  11. It will open a new window in the Business Manager
  12. Set a name to your MDM server in
  13. Confirm the checkbox selection default:
    Allow this MDM Server to release devices.
  14. Add public key that you previously downloaded (in step 7) by clicking on
  15. After the Server is created, open it, and download the Token  by clicking Download Token.

  16. Go Back to MDM tab in Intune, and enter your Apple ID (the email address that you used to register to your apple manager account). You should be back at the page below:
  17. Now add your Apple ID in
  18. And then upload your Apple token file to the section below

    (The file that you are uploading is the file that you downloaded in step 15 above)
  19. Set Profile in Enrollment tokens, in the window below:
  20. In the left side menu, click Menu > Profiles to display:
  21. Click Create profile
    Set all desired options or/and choose a default profile
  22. Once the new profile is created, navigate to Tenant admin window
  23. In the menu on the left, select Connectors and tokens.
  24. In the newly displayed window, select Connectors and tokens VPP
    Then choose Apple VPP Tokens

  25. Create a new VPP token name
  26. Open Apple Business Manager in a separate window/tab
  27. In the new tab, go to Apple business  > Apps & Books >  Download token
  28. Go back to the VPP token tab, as seen in step 25, and enter the missing information in

    Specify the Token Name as TeleMessage TM SGNL
    In the Apple ID enter your manager’s email ID used to sign into the Apple business manager
    And upload the VPP token that you downloaded in step 27. To the MDM
  29. Continue to the next step, and set the Settings > Add scope tags > click Create to finish.
  30. Go back to the Apple Business manager tab.
    Navigate to the MDM Server created. As seen in the image below.
    Click the blue MDM Server Assignment on the left:
  31. On the dropdown menu on the right, choose the MDM server that you created.

    To all the device types that you intend to manage (iPhone, or additional devices)
    And click on Done
  32. Go back to the main Intune MDM interface.

    and select Apps, opening a page with all your apps overview
  33. Choose All Apps, or iOS/iPadOS apps in the middle left menu.
  34. Now enroll devices from MDM and assign to desired app from Apple Business, in the screenshot below:
  35. Choose the iOS/iPadOS apps you are interested to add to your organization from the list on the right (image above)
  36. The specific app you choose will be opened, so you can change their properties.

    Note: Provide the proper assignments to the apps.
    In the window below click Assignments > Edit
  37. This will open the assignment window, and provide the required assignments:

    Important: Before this stage, you should already create your users, groups or devices, because you are now going to assign the app permissions to the selected.
    Click ssigning the required permissions to your group as seen below:
  38. After we assigned the information to the group, click Review + save, as seen below:
  39. The Purchased app(s) will appear in a list as iOS volume purchase program app
  40. Go to All apps > iOS apps > Search for desired purchased app and assign it to device /Group
  41. The purchased application(s) you selected, will be deployed on the devices in about 15 minutes, and your employees can start using those.

Good luck with enrolment!

For more information, please watch this video.



Skip to content