Add a free iOS App Store app by URL (no VPP)
For genuinely free apps where an Apple ID on the device is acceptable, add straight from the App Store — no token needed. Not silent and no licence tracking; paid apps must use VPP.
Every step below can be done by hand. Or connect your Microsoft tenant to Decolla once, and Decolla performs this for you over Microsoft Graph in your own tenant — then hands back a verified result you can see and roll back per item. It also puts the fundamentals this step depends on in place — the target group, the licence allocation — so a build is never blocked half-way by a missing dependency.
- Intune Administrator (or Application Manager) sign-in for the Intune admin center.
- The exact app name as it appears in the App Store - close matches pull the wrong listing.
- The correct App Store country/region for your users, which pins the app's store URL.
- The Entra ID group(s) you'll target in the Assignments step.
- Go to Apps > All Apps > Create.
- Under 'Store app' select 'iOS store app', then click Select.
- Click 'Search the App Store'.
- Choose the App Store country/region, type the app name, pick it from results, then…
- Confirm the auto-filled Name, Publisher, Appstore URL, minimum OS and device type,…
- Scope tags (optional) > Next; Assignments (add Entra groups) > Next.
- Review + create > Create.
If it goes wrong
The failures people actually hit on this process, each with the diagnosis and fix:
- Apple tokens in Intune: APNs, ADE and VPP renewal explained — The APNs certificate, ADE enrolment token and VPP token all expire yearly and each breaks something different. A one-page matrix and the renewal rules.
- Duplicate apps in Intune after VPP token renewal — Renewing an Apple VPP token as a new entry duplicates every app in Intune. How to renew in place, recover from duplicates, and catch early expiry.
- Renew or recreate the Apple MDM push certificate in Intune? — Renew — never recreate — your Intune APNs certificate. Why device trust follows the push topic, what the Apple ID actually controls, and the safe path.
See it on a real device.
Decolla is in private build — early-access members see a build defined, deployed and rolled back first.
Get early access