Skip to content
Avanet

Apple Business Apps in Sophos Mobile: Manage Content Tokens and Licenses

Verify before use in your own tenant: Tenant permissions, supported devices and management modes, the documented menu paths, token renewal, and effects on production devices have not been tested in a test tenant. This guide is based on vendor documentation, not on a tenant or device test. Before proceeding, an active MDM-capable license, the appropriate admin role, and a supported managed-device mode are required. Before a rollout or token change, a pilot, a review of existing assignments, and a clarified rollback path are required; plan a change of MDM service only as a controlled token cutover after assessing the impact and approving the interruption and its timing.

Scope and token boundaries

This guide covers Apple Business app licenses for iOS, iPadOS, and macOS and the content token used to manage apps in Sophos Mobile. Through Apple Business, organizations can purchase app licenses in volume for internal distribution; Sophos Mobile integrates their assignment to users or devices. The general app pages distinguish installation by administrators from user-initiated installation through Sophos Mobile Control. Managing other apps, app packages, app configurations, and general installation tasks is a separate workflow. Before proceeding, check for an active MDM-capable license, the appropriate admin role, and a supported managed-device mode: Sophos Mobile Device Management or Sophos Mobile includes MDM; according to the license overview, Sophos Mobile Threat Defense alone covers management of the Threat Defense apps, not MDM features. The license overview alone does not establish that the Apple VPP interface is available in every tenant.

Keep installation and license assignment separate: According to Sophos, Apple Business apps are installed through Sophos Mobile like other apps, using the general installation routes initiated by an administrator or by a user through Sophos Mobile Control. In addition, users on iPhones and iPads can install Apple Business apps from the App Store. Sophos does not document this additional App Store route for Macs; this does not rule out installing Mac apps through Sophos Mobile. A license assignment alone is neither an installation task nor proof that an app is installed.

Do not confuse these tokens: Sophos documents Setup > Apple setup > Apple VPP for the content token (.vpptoken) used to manage app licenses; check the actual menu navigation in the tenant before making changes. Under Apple DEP, by contrast, a service token is set up for device management/ADE; it does not replace the content token. According to Sophos, resetting the DEP integration deletes the service token as well as Apple Business devices and profiles — it is not a way to synchronize app licenses. APNs certificates are another separate process. The ADE path and any reset belong in separate device-enrollment planning, not in this app guide.

Apple app catalog and installation task

For ordinary iOS/iPadOS apps, you can add an App Store link or an app package. For macOS, the general Sophos app overview also lists store links, and the macOS settings page describes a Link field. However, the specific Add app selection list does not list an ordinary macOS store link, but macOS package; Apple Business apps are loaded separately through Import VPP apps. A selectable route for an ordinary macOS store link is therefore not established here and is not presented as a procedure to follow. This is neither a claim that such a route is technically impossible nor a user’s installation from the App Store. The app deployment guide explains the general catalog and installation workflow.

To install an app on a device, you can create and transfer a task bundle containing Install app. For iPhones and iPads, you can also create these installation bundles directly on the Apps page; this shortcut is not established here for Macs. The task bundle lifecycle covers creation and transfer. Catalog entry, license assignment, and actual installation remain separate checks.

In-house iPhone/iPad apps: In-house iOS/iPadOS apps can be distributed from uploaded .ipa files. To do this, create the app’s provisioning profile and make it available on the target devices: either install it separately beforehand or include it in the .ipa. This app profile is neither an MDM enrollment profile nor a content token. Sophos Mobile can distribute it to iPhones and iPads; the app provisioning profile workflow explains import, assignment, and the User Enrollment restriction.

Preparation and content token

  1. Document the owner of the Apple Business location or organizational unit, the Sophos Fusion tenant, any MDM service already in use, app licenses, expiration date, and the Managed Apple Account used to download the active content token. In particular, review existing user and device assignments before changing tokens; test the effects of revocation in the other MDM and renewal here in a pilot. Do not revoke a token still in production as a precaution. When switching MDM services, Sophos recommends revoking a token used by the other service and removing it there before uploading it to Sophos, so it is not assigned to two services at once. Plan this step only as a controlled cutover after inventorying app, user, and device assignments, assessing effects on ongoing operations, and approving the interruption and its timing; revoke or remove it only after the transition is clear, then check assignments and app state in the pilot. Neither use the token in both services simultaneously nor assume automatic license release or a tested rollback path. Keep the scenarios separate: Changing MDM services while retaining the same Apple organizational unit is not automatically a license transfer. If the Apple organizational unit is also changing, check available and already assigned licenses separately for each unit: Apple describes transferring unassigned licenses between organizational units as a separate process; uploading the token does not transfer those licenses. Consider such a transfer only when the unit is changing, not by default for every MDM change. Apple’s migration of older user-based tokens and a switch to Apple’s integrated device management service are different scenarios and are not covered here.
  2. In Apple Business, use the Administrator or Content Manager role to download the content token for the organizational unit containing the relevant apps. Sophos warns that a content token may be used in only one device management service; for multiple relevant organizational units, Sophos requires separate Sophos Fusion accounts.
  3. According to the Sophos documentation, in Sophos Mobile under Setup > Apple setup > Apple VPP, check the Apple Account address, the appropriate App Store country, the automatic assignment model, and, if applicable, app updates; do not force the documented menu path if the tenant interface differs. The configured App Store country determines app search results in Sophos Mobile; some apps are not available in every country. If an app is missing from search or import, check availability in the configured country before assuming a license or token error. Then upload the downloaded .vpptoken file. Compare the displayed organization and expiration date with the intended source before saving. Do not copy the token file into tickets or public storage.
  4. The content token is valid for one year. Apple warns that changing the password of the Managed Apple Account used to download the existing token also invalidates it before then; communication about app and book licenses between Apple Business and the external MDM service then stops. To avoid interruptions, Apple recommends a manually created Managed Apple Account with a dedicated role whose only permission is “Assign licenses for Apps and Books” for downloading and managing content tokens; Sophos specifies Administrator or Content Manager for its setup. Check whether the restricted role works in the specific Apple/Sophos context before using it; do not assume an existing token stays valid merely because the account is changed. Identify the account used to download the active token and treat its password rotation as a planned token change because it invalidates the token: clarify the impact, interruption, and tenant-specific recovery path with a pilot in advance; do not assume a silent or automatically successful renewal. Monitor expiration and plan renewal before it expires, using the same intended Apple Business location/organizational context. The Sophos section reviewed describes download and upload but provides no validated sequence of steps for renewal or recovery after a password change; do not present this as a tested replacement or guaranteed recovery. Before downloading or uploading again, open the current Apple guide to managing and downloading content tokens for the relevant organizational context and check the active tenant, record assignment and license state, and compare again on pilot devices after the replacement. The Apple guide does not establish a recovery path tested in Sophos.

Automatic assignment: The Automatically assign iOS VPP apps on installation setting determines whether and how the license is assigned automatically when a user initiates installation. It does not start app installation itself or replace a separate installation task. “Prioritize device assignment” favors devices and falls back to the user when device assignment is unsupported (Apple User Enrollment supports only user assignment). “Prioritize user assignment” favors users and falls back to the device when there is no device user. “Disabled” requires manual assignment. Both priority modes enable automatic device assignment; even with “Prioritize user assignment,” assignment to the device is the fallback when there is no device user. Mac apps cannot be assigned to users. When Automatically update iOS VPP apps is enabled, according to the documentation Sophos automatically updates device-assigned apps on devices with Apple Device Enrollment and user-assigned apps on devices with Apple User Enrollment; for user-assigned apps under Apple Device Enrollment, users must check for updates in the App Store. Do not infer a successful update solely from the enabled option.

Assign users and apps

For the Sophos-documented invitation path for user licenses, invite only the approved people under People after setting up the content token; Sophos requires an invitation before assigning an app to a user in this documented workflow, but not for device assignments. Invite users to Apple VPP on the People page invites all users; for an individual already listed there, select the person and use Invite user to Apple VPP on Show user. If the person is not on the People list, select Search and invite a user to Apple VPP, search by name, email address, or part of either under Search users, select the person under Select user, and click Apply. Sophos sends an invitation email with an activation link. Under Show user > Apple VPP, “Registered” does not yet mean activated; “Associated” means activated. For managed distribution to a personal Apple Account, the user must accept the invitation; limit invitations and deregistrations to approved users. With account-driven Apple User Enrollment, sign-in instead uses a Managed Apple Account; signing in with a personal Apple Account cannot accept the managed-distribution invitation in that mode. The Sophos documentation here does not establish how its invitation and assignment map to that account-driven identity: verify account, license assignment, and installation in an authorized pilot; do not prescribe a personal-account invitation or identity switch as a universal BYOD prerequisite. No invitation is needed for device-only assignments.

On Show user, in the Apple VPP section, you can also deregister the user from Apple Business. This is neither deselecting an app assignment nor unenrolling a device with Unenroll. The effects of deregistration on accounts, apps, data, or licenses, and whether it can be reversed, are not established here; do not infer a cleanup or recovery procedure from this.

For a manual assignment, use Import VPP apps under Apps > iOS & iPadOS or Apps > macOS to fetch the app entries; the VPP column identifies these apps. In the app details under VPP licenses > Show, select either users with the Apple Business status Registered or Associated, or managed devices. Registered is sufficient for selection during manual assignment; however, this status does not establish that the account is activated or that the app is usable. Optionally, in this manual workflow, you can assign the app to devices through device groups: click Show next to Available to device groups and select the intended groups. Then save. Sophos recommends device assignment for easier deployment. iOS/iPadOS supports user or device assignment; Apple User Enrollment supports only user assignment, and macOS only device assignment. According to Sophos, iOS apps are installed as managed by default. Sophos documents the Sophos Mobile managed installation option for iOS; deselecting it is supposed to install the app unmanaged. Before a BYOD rollout, check on an authorized pilot device whether the app is already installed privately, how reinstallation and any consent to management work, and what effect the option actually has under the specific OS and enrollment mode. With account-driven Apple User Enrollment, an app already installed privately cannot be brought under management; do not promise a silent conversion or takeover. Before saving, compare license capacity, target group, and ownership/mode boundaries against the pilot inventory. The display on the device may lag behind Apple-side synchronization; saved alone is not proof of installation.

Check assignment scope before choosing a license: Sophos says a user-assigned app can be installed on all of that user’s Apple Business-managed iPhones and iPads; device assignment on iPhone/iPad does not require associating an Apple Account. A Mac-assigned app is available to all users signing in to that Mac, not only the person named in a deployment request. Confirm the intended devices and shared-Mac access in the pilot before assigning; this is a license and availability distinction, not proof of installation or access to another user’s app data.

Checks, discrepancies, and revocation

Data-loss preflight for iPhone/iPad: Before deselecting an assignment, removing an app, or unenrolling a BYOD device, determine whether the app is managed on that particular device, how it is installed and managed, and which enrollment mode applies. According to Apple, removing a managed iPhone/iPad app also deletes the data in its app container; unenrolling from account-driven User Enrollment always removes the associated managed apps. First clarify ownership of any needed app data, permitted export or backup, and a verified recovery path, and test this in an authorized pilot. The separate BYOD/User Enrollment guide addresses unenrollment and its consequences; this license guide does not replace it. Revoking a license alone does not mean immediate app removal, and reassigning it does not restore deleted local data.

  • First check Apple Business license inventory, VPP assignment, and actual installation or update capability on a pilot device separately. On Show user, in the Apple VPP section, you can view the apps installed by that user; this user-specific view does not replace checks on the pilot device. For performance reasons, Sophos keeps a local copy of license information. Only if its display differs from Apple Business, trigger resynchronization under Setup > Apple setup > Apple VPP > Clear VPP cache, then compare again. The cache button neither renews a token nor releases a license.
  • Revoke iPhone/iPad app assignments: Complete the data-loss preflight above first; then deselect users or devices in the app details; on iOS/iPadOS, the user details page is another option. Deselecting does not reliably mean immediate removal or immediate loss of usability: For its documented assignment/revocation workflow, Sophos describes possible continued use of Apple Business apps for 30 days after an assignment is removed. This is not a universal grace period or guarantee that apps and data will be preserved under other installation/management methods or after BYOD unenrollment. Apple distinguishes different consequences of license revocation depending on the app management method; without product testing, that does not establish which Apple management method Sophos uses. Plan access separately, and before completing offboarding check the actual app, data, and license state on the affected device. Sophos says device-bound licenses are released automatically when the app is uninstalled or the device is unenrolled, but user-bound licenses are not. Therefore check user assignments separately after offboarding. Reassignment does not guarantee restoration of app data already deleted.
  • Revoke a Mac app assignment: First clarify the affected Macs and users, needed app data, and the reinstallation path. Under Apps > macOS, for the VPP app (checkmark in the VPP column), click the arrow next to the app and choose Unassign from the action menu; select individual devices or Select device groups, under Schedule task, choose Now for an immediate request or Date for a later request and set both the day and time, then click Finish. As a separate route, Sophos documents transferring a task bundle containing Unassign VPP app to the target Mac. Both routes withdraw the assignment; a completed task does not yet prove that the app has been removed. Sophos reports the license revocation to Apple; Apple handles uninstallation. For this Sophos-documented Mac revocation workflow, the app may initially remain on the Mac but cannot be updated without reassignment; Sophos specifies a 30-day period while also noting that removal can take days even with “Now.” This period is not a guaranteed protection or retention period for other app management methods. Check the actual installation/management method and the app, license, and data state on the affected Mac before considering revocation complete; do not assume either task completion or immediate removal. If the assignment was made in error, reassign only after rechecking the license and user, and monitor device state; doing so does not guarantee recovery of app data already removed.