# Content Token (VPP) Management Apple Content Token (VPP) Management refers to the process of integrating your organization's ABM/ASM account with ManageEngine MDM using a Content Token/VPP (Volume Purchase Program) Token. This token acts as a secure, authenticated bridge between Apple and MDM. It allows you to: - **Synchronize Applications:** Discover and import a catalogue of apps you've purchased or assigned in ABM. - **Manage Licenses:** Assign, revoke, and track the usage of app licenses across your enrolled devices without using Apple IDs. - **Enable Automated App Distribution:** Distribute apps to devices or users seamlessly. Video: https://www.youtube-nocookie.com/embed/BpgKEgCQ6Ls?si=p6qfKGM1PnWcfFWJ ## Integrate a New Content Token (VPP) in MDM **Note:** Only a MDM user with the "MDM Admin" role and "Application Management Full Control" privileges can perform this action. 1. On the MDM Console, navigate to **Device Mgmt → App Management → Apple App Management**. Select **Configure apps for Business** or **Configure apps for School** as your preference. 2. Log in to ABM/ASM with your corporate credentials. 3. On the ABM portal, click on your Organization name → **Settings**. ![Step1: Navigating to settings on the ABM portal to facilitate Apple app management.](https://www.manageengine.com/mobile-device-management/help/images/abm-stoken1.png) 4. Navigate to **Payments and Billing → Apps and Books → Content Tokens**, and download the required content token. ![Step 2: Downloading server token on the ABM portal to facilitate iOS app management.](https://www.manageengine.com/mobile-device-management/help/images/abm-stoken2.png) 5. Click the **Download** button next to your MDM Content Token entry. If your MDM Content Token is not listed, you may need to add it first. 6. Save the downloaded (.vpptoken) file securely. 7. Navigate back to the MDM Console and upload the Content Token by browsing and selecting the .vpptoken file downloaded from ABM. 8. The Content Token is valid for one year and must be renewed annually upon expiry. Provide your email address to receive notifications prior to expiration. Click **Upload** to complete the process. 9. You have successfully created/renewed the content token on the MDM server. You can now distribute apps to managed devices and assign or revoke licenses as required. 10. Upon successful upload, MDM will immediately initiate a sync with ABM and import all associated apps and available license counts. **Note:** If this Content/VPP token was previously associated with another MDM server, uploading the new token here will automatically revoke licenses from devices assigned from the previous server. Once revoked, apps installed from the previous server will automatically uninstall after 14 days. ## Renew an Expired Content Token Video: https://www.youtube-nocookie.com/embed/8y-vEYQpP8U?si=htMuJAbxyy0j-0-H 1. **Each Content token (VPP/Apple Content Token) is valid for one year.** When nearing expiration, the token must be renewed to continue distributing apps. 2. The MDM console displays expiration notifications. 3. To renew, generate a new token from the same location in ABM (**Payments and Billing → Apps and Books → Content Tokens**). The old token becomes invalid upon generation of the new one. 4. To upload the content token on the MDM server, go to **Device Management → App Repository → Apple App Management**. Choose the required content token and click **Renew Token**. ![abm-stoken3](https://www.manageengine.com/mobile-device-management/help/images/abm-stoken3.png) If multiple content tokens are present, click the token to be renewed, choose **Actions**, and select **Renew Token**. ![abm-stoken4](https://www.manageengine.com/mobile-device-management/help/images/abm-stoken4.png) 5. Upload the new .vpptoken file. MDM will re-establish the connection and resume syncing app and license information. ## Managing Multiple Content Tokens in MDM You can upload multiple content tokens on the MDM console to manage department- or location-specific app purchases. To upload new tokens: - Navigate to **App Repository → Apple App Management → Add Content Token → Upload Token**. - Once uploaded, MDM syncs apps associated with the content token via ABM. **Note:** 1. To add a new location in the ABM portal, go to **Locations** and click **Add a new location**. Use descriptive names for easier identification. 2. When distributing apps via Apple Configurator, it is recommended to create and maintain a separate Content/VPP token. ## Content Token (VPP) Management Scenarios and Effects ### 1. Content Token Used Simultaneously in MDM and Apple Configurator **Scenario:** The same ABM Content/VPP token is configured for app distribution in both the MDM server and Apple Configurator. **Cause:** A Content/VPP token can be actively used in **only one location at a time**. Using it in both systems causes synchronization conflicts. **Effect:** - MDM displays a warning indicating the content token is already in use. - Licenses will not be available for assignment until resolved. **Steps to resolve the conflict:** 1. Open **Apple Configurator** on the configured Mac. 2. From the top menu bar, navigate to **Account**. 3. Verify the signed-in **ABM account** and the **content token (location)** in use. 4. Select **Change Location** and choose a different, unused content token. ![Apple Configurator Content Token Screen](https://www.manageengine.com/mobile-device-management/help/_drupal/mobile-device-management/images/apple_ct.png) 5. Navigate to the **MDM Console** and perform a **manual app sync**. 6. If prompted that the token was previously used in Apple Configurator, acknowledge and continue. 7. Once sync completes, app distribution will resume normally. **Note:** Maintain a **separate Content/VPP token** exclusively for Apple Configurator to avoid conflicts. **If your organization uses only one Content Token:** - **Create a new Content Token (Location) in ABM:** Go to **Locations** and add a new location to generate a separate token. Assign the new token to Apple Configurator and retain the original for MDM. - **Sign out of ABM in Apple Configurator:** If no longer needed, open Apple Configurator → **Account** → Sign out to release the token. ### 2. Removing a Content Token (VPP) from MDM **Scenario:** An administrator removes a Content/VPP token from the MDM configuration. **Effect:** All apps synced exclusively from that token will be revoked. MDM attempts to revoke all assigned licenses and sends uninstall commands to affected devices. **Note:** Remove a token only if you are certain it is no longer required and you intend to reclaim all licenses in ABM. ### 3. Managing Duplicate Apps (Multiple Tokens) **Scenario:** The same app is available from two different Content/VPP tokens uploaded to the same MDM. **Effect:** - The app appears only once in the application repository. - MDM creates a combined pool of licenses from all tokens containing that app. - During assignment, MDM automatically consumes licenses from any available token. ### 4. If the Content Token Is Already in Use ![Content Token Already in Use](https://www.manageengine.com/mobile-device-management/help/images/lt-1.png) 1. **Used in another MDM Server:** If the same token is synced with another MDM server, a prompt indicates prior usage. Selecting the checkbox removes app licenses linked with the other MDM server. 2. **Used in Apple Configurator:** If synced via Apple Configurator, a prompt indicates prior usage. Selecting the checkbox removes associated licenses from Apple Configurator and syncs with the current MDM server. ### 5. Token Expiry or Revocation - **Expired/Revoked Token:** MDM cannot sync with Apple for that token. - **Existing Assignments:** Apps already installed continue to function. - **New Assignments:** New licenses or app assignments cannot be made until a renewed token is uploaded. ## Troubleshooting Tips **1. MDM server is not able to contact ABM to sync apps.** Ensure `vpp.itunes.apple.com` is allowlisted along with other required [domains](https://www.manageengine.com/mobile-device-management/faq.html#g2) and [ports](https://www.manageengine.com/mobile-device-management/faq.html#g1). Ideally, allowlist `*.apple.com` for seamless Apple device management. Verify required [Apple services](https://www.apple.com/support/systemstatus/index.html) are operational. **2. Why does an App Store app remain visible in the ManageEngine repository after its license is moved to an unmanaged location in Apple Business Manager, and how can it be removed?** ManageEngine Mobile Device Manager Plus does not automatically remove apps from the repository if licenses are moved or unassigned. The app remains visible with a zero license count until manually deleted. To resolve this, manually remove the app from the ManageEngine app repository. Ensure the app is properly synced from ABM and distributed via MDM for seamless installation. ## FAQ 1. **How do I migrate iOS VPP apps from an expired Apple Business Manager (ABM) content token to a new one to ensure automatic deployment without manual intervention?** To resolve deployment failures caused by an expired or incorrect ABM content token: - Ensure all applications from the old token are added and available in the new content token. - Redistribute these applications to the appropriate device groups using the new token. - Verify that applications are using licenses from the new token on both existing and newly enrolled devices. - Once validated, safely remove the old content token. This ensures future deployments automatically use the correct license key.