Last updated: July 24, 2026
This guide explains how to migrate Apple VPP/DEP accounts to Apple Business Manager (or Apple School Manager for education), which Apple mandated to unify device, app, and content management under one console with stronger security and role-based access. Admins upgrade via the VPP/DEP portal, create a Managed Apple ID, set up two-factor authentication, migrate purchased apps and locations, and invite VPP purchaser accounts, after which existing tokens keep working until they expire.
To simplify managing Apple devices and apps, Apple has combined the capabilities of the Device Enrollment Program (DEP) and Volume Purchase Program (Apple VPP) to a single portal known as Apple Business Manager (ABM). As Apple mandated migration from Apple DEP and Apple VPP to ABM before December 1, 2019, organizations can migrate their accounts by following the steps given in this document. In case of an educational institution, you can upgrade to a similar portal known as the Apple School Manager.
Migrating to Apple Business Manager from Apple VPP/DEP also provides organizations multiple benefits such as:
Follow the steps given below to upgrade Apple Volume Purchase Program and Device Enrollment Program portals to ABM/ASM by migrating from Apple VPP/DEP to ABM/ASM:



Note: Ensure two-factor authentication is enabled for the DEP account to access the ABM portal or set it up by logging in to Apple ID portal.




Once this is complete, all the previously purchased apps from legacy Apple VPP are visible on the portal.


For more information, click here.
Note:
Once you upgrade to the new portal, all your managed devices and apps will be available in ABM. You can continue managing these devices and apps using Mobile Device Manager Plus, without changing the tokens till it expires after which, you will have to regenerate the tokens from the ABM portal.
On the ABM portal, the DEP agent is called the Administrator and there can be a maximum of five administrators. After migration to the ABM portal, you can find all your organization's accounts available there. You need to associate these accounts with locations and roles where each role has a set of privileges. If the account was already an admin in either DEP or VPP, these roles are automatically assigned to them. Additionally, the Device Manager role must be assigned to any other account managing the devices and Content Manager role to the accounts responsible for managing your organization's apps. Here, the admin capable of creating or editing other admin accounts is called the People Manager.
The Server Tokens for managing apps in the ABM portal are created based on different locations instead of users. This means that any apps added to that location can be managed by all the technicians responsible for that location.
Note: After upgrading, if any of your apps are not automatically available in Mobile Device Manager Plus, upload the Server Token from the ABM portal to sync all your apps. If the problem still persists, contact mdm-support@manageengine.com or mdmcloud-support@manageengine.com.
ABM gives you a unified console to manage devices, apps, and content, an ABM-specific Managed Apple ID that can't be used for iCloud or iTunes, role-based access control, and the ability to transfer app licenses between locations based on usage.
Your tokens keep working without any changes until they expire, after which you'll need to regenerate them from the ABM portal.
Accounts that were already admins in DEP or VPP get their roles carried over automatically; you'll additionally need to assign the Device Manager role to accounts managing devices and the Content Manager role to accounts managing apps.
Upload the Server Token from the ABM portal to sync your apps. If the problem still persists, contact mdm-support@manageengine.com or mdmcloud-support@manageengine.com.