HomeSetup guides › Upload the VPP/location token into Intune
Setup guide · from scratch

Upload the VPP/location token into Intune

Creates the Apple VPP connector in Intune from the .vpptoken you downloaded in ABM. The Apple Account you enter MUST exactly match the Managed Apple ID that owns the token or it shows invalid.

Intune admin center (Tenant administration > Connectors and tokens > Apple VPP tokens)
≈ 10 min
Apple — iPhone, iPad & Mac · step 7 of 12 · ≈ 10 min‹ PreviousNext ›
The Decolla way — skip the clicks.

Every step below can be done by hand. Or connect your Microsoft tenant to Decolla once, and Decolla performs this for you over Microsoft Graph in your own tenant — then hands back a verified result you can see and roll back per item. It also puts the fundamentals this step depends on in place — the target group, the licence allocation — so a build is never blocked half-way by a missing dependency.

⏱ By hand: about 10 min of clicking, every build. The Decolla way: part of one tenant connect, then automatic.
Before you start
  • The .vpptoken file you downloaded from ABM, saved somewhere you can browse to it.
  • The exact Managed Apple ID email that owns that token - copied, not typed from memory.
  • An Intune Administrator sign-in for intune.microsoft.com.
  • The country/region of your canonical App Store, decided in advance.
0 of 9 done
Step 1. Sign in to https://intune.microsoft.com as an Intune Administrator.
Screenshot: Intune admin center home (captured during a live customer build — coming to this page)
Why: This lands under Tenant administration, a tenant-wide area, so it needs the Intune Administrator role named here rather than a device-only operator account.
Step 2. Go to Tenant administration > Connectors and tokens > Apple VPP tokens.
Screenshot: Empty Apple VPP tokens list before Create (captured during a live customer build — coming to this page)
Why: This blade is where Intune keeps the VPP connector - a tenant-level object every managed device shares, which is why it sits under Tenant administration rather than per-app.
Watch for: Make sure you're on the Apple VPP tokens tab specifically - 'Connectors and tokens' hosts several different connector types.
Step 3. Click 'Create' to open the four-page wizard.
Screenshot: Create VPP token wizard Basics page (captured during a live customer build — coming to this page)
Watch for: It's a four-page wizard (Basics, Settings, Scope tags, Review) with no half-way save - have the .vpptoken file and Managed Apple ID ready before you click Create.
Step 4. BASICS: enter a Token Name, the Apple Account (Managed Apple ID email that owns the token), and browse to the .vpptoken file; Next.
Screenshot: Basics page with the three fields filled (captured during a live customer build — coming to this page)
Why: The Apple Account binds this connector to the exact Managed Apple ID that owns the token, so Intune can buy and assign licences under it with no Apple ID on the device.
Watch for: The Apple Account must EXACTLY match the Managed Apple ID that downloaded the token in ABM - a mismatch shows the token invalid moments after Create, with no error on this page.
Don’t: Do NOT retype the Managed Apple ID from memory or reuse an old personal Apple ID - copy it from ABM; one wrong character fails as 'invalid'.
Step 5. SETTINGS: set 'Take control from another MDM' only if migrating; set Country/Region to your canonical store; Type of VPP account = Business; Automatic app updates = Yes.
Screenshot: Settings page fields (captured during a live customer build — coming to this page)
Why: Country/Region fixes which App Store catalogue you license from, Type of VPP account = Business marks it an organisation (not education) token, and Automatic app updates = Yes lets apps self-update without you re-pushing them.
Watch for: 'Take control from another MDM' is a live migration switch - flipped on while another MDM still owns the token, it drags the licences across and can strip VPP apps from those devices.
Don’t: Do NOT set Country/Region to a store you don't actually buy from - app availability and licences differ per country and it is awkward to unpick afterwards.
Step 6. Tick 'I grant Microsoft permission to send both user and device information to Apple' and select 'I agree'; Next.
Screenshot: Permission-agreement tick (captured during a live customer build — coming to this page)
Why: This consent lets Intune send Apple the user and device identifiers it needs to assign and count licences - without it the connector cannot manage apps at all.
Watch for: Miss the tick and the 'I agree' button stays inactive, so you can't advance past Settings.
Step 7. SCOPE TAGS: optionally add scope tags; Next.
Screenshot: Scope tags page (captured during a live customer build — coming to this page)
Why: Scope tags decide which admin roles can see and manage this token - useful when separate teams run separate ABM Locations.
Don’t: Don't add tags for the sake of it - leave them blank if one team runs everything; you can apply them later.
Step 8. REVIEW + CREATE: check the values and click Create.
Screenshot: Review + Create summary (captured during a live customer build — coming to this page)
Why: Last chance to check the Apple Account and file before the connector is built - fixing a typo here is far cheaper than deleting and recreating the token.
Watch for: On Create, Intune calls Apple to validate - a wrong Apple ID won't fail here; it surfaces as 'invalid' on the list a moment later.
Step 9. Confirm the token lists with a green/valid status and expiry date.
Screenshot: Token list showing valid status + expiry (captured during a live customer build — coming to this page)
Why: A green/valid status means Intune authenticated to Apple with the token - only then will a sync pull your ABM apps into Intune.
Watch for: Stuck on invalid almost always means the Apple Account didn't match the token's Managed Apple ID - fix the account, don't re-download the token.
On a schedule: The expiry shown is your renewal deadline (VPP tokens run about 12 months) - diarise it now; let it lapse and app assignments stop, and re-uploading can spawn duplicate apps in Intune.

Put these on a schedule

StepRecurring action to diarise
Step 9The expiry shown is your renewal deadline (VPP tokens run about 12 months) - diarise it now; let it lapse and app assignments stop, and re-uploading can spawn duplicate apps in Intune.

If it goes wrong

The failures people actually hit on this process, each with the diagnosis and fix:

See it on a real device.

Decolla is in private build — early-access members see a build defined, deployed and rolled back first.

Get early access