The Apple Volume Purchase Program (VPP) allows administrators to purchase application licenses in bulk and then allocate them to device users as necessary. VPP is part of Apple's Deployment Program which also includes the Device Enrollment Program (DEP), also supported by MobiControl.
Once registered with VPP, administrators can use MobiControl to distribute the applications and their licenses to enrolled devices using Application Catalog rules.
Visit the Apple support website for more information on how to participate in the Volume Purchase Program. Please note that although VPP allows you to purchase licenses for books as well as applications, MobiControl does not support licensing for books.
VPP can be deployed in two methods: Redemption Codes or Managed Distribution. See VPP Licensing for more information.
Creating an Apple VPP account enables you to purchase licenses for applications on the VPP store. Once you link your VPP account to MobiControl, you can distribute those applications to MobiControl enrolled devices using VPP. Note that you only require a VPP account if you are using the Managed Distribution deployment method. Redemption codes do not require a VPP account.
You can create as many administrators for your corporation as necessary. However, licenses purchased for each administrator are separate and are not shared between administrators.
Use the Manage Apple Volume Purchase Programs dialog box to add, edit, or delete VPP tokens. VPP tokens link your MDM server with your VPP account. They enable the deployment server and the VPP store to exchange information regarding the VPP licenses that have been purchased and the number of licenses that have been distributed to device users. One VPP account can have multiple tokens although you do not necessarily need a separate token for each different server. To keep your VPP account valid, you must install a new token on your MDM server once a year. Download your tokens from the Apple VPP store, then upload them to a MobiControl deployment server.
Note
If you upload the same VPP account token twice, MobiControl treats them as two different connections.
You must configure B2B applications before you can apply their licenses to devices using application catalog rules. If you do not fully define the application by entering its Name and Bundle ID (as instructed below), the application is not visible in the Application Catalog rule dialog.
This only deletes or disassociates the VPP account from a specific instance of MobiControl. You will still be able to use your VPP account in another instance of MobiControl or another MDM.
Depending on your deployment solution, it might be advantageous to have the same VPP accounts running on multiple MDM instances, MobiControl or otherwise. However, this can cause confusion when determining which instance has ultimate access and authority over distributing licenses. To help counteract the confusion of multiple instances accessing VPP accounts, Apple has developed the concept of Ownership. VPP accounts and their licenses cannot be modified or distributed unless they are 'owned' or 'claimed' by an MDM instance.
In MobiControl, you can view and claim (or reclaim) ownership from within the Apple Volume Purchase Program dialog window. If the status is Valid that means that you have ownership of the VPP account and can distribute or revoke licenses freely. If the status of the VPP account is Not Owned, you have to reclaim ownership before MobiControl can assign or revoke any further license to iOS devices managed by that instance of MobiControl.
The Deployment Server creates a log event whenever ownership is lost or recovered.
Additionally, you can use Clean Up to revoke VPP licenses that are part of the VPP account but were assigned by either another instance of MobiControl or another MDM. These newly released licenses become available to use within this instance of MobiControl.
Note
MobiControl may occasionally assign VPP licenses to Apple ID endpoints that are unmanaged and created by different MDM instances. A Clean up request retires these unmanaged endpoints and re-assigns the licenses to a managed endpoint. This may cause MobiControl to require the user to accept Apple’s Terms of Use again.
If you are using a single VPP account across multiple instances of MobiControl (or other MDMs), make sure there is clear communication between the people managing VPP licenses.