Jump to:navigation, search
Wiki





























De.png
En.png
Fr.png






Installing special apps on iOS devices
New article with version: 1.14
notempty
This article refers to a Resellerpreview

Access: portal.securepoint.cloud  Mobile Security iOS/iPadOS  Apps

Introduction

This HowTo describes how to install customized apps and unlisted apps in Apple School Manager and Apple Business Manger accounts and manage them using the Securepoint Mobile Security Management Portal.

  • Custom Apps: specially developed apps that are only accessible to users of one's own organization/company
  • Unlisted Apps: non-public apps that are distributed individually to users, or to devices.



Installation of a customized app

Requirement customized apps

In order for an app to be distributed as a customized app

Here is additional information about customized apps on iOS devices.

The customized app is deployed to the MDM portal and managed via it. Access must be available.

Set up customized app in App Store Connect

If the app is not yet set up in the App Store Connect, this is done with the following steps:

  1. Log in to App Store Connect as Account Holder, App Manager or as Admin.
  2. in My Apps click on the button Add (+)
  3. In the pop-up window, click New App
  4. in New-App-Dialog select the platforms iOS and enter the app information
  5. select User Access Limited Access and select the Apple School Manager or Apple Business Manager account.
  6. Click on Create
  • For customized apps, the identical app review guidelines from the App Store apply. This can take 1 to 2 days.
  • If the customized app contains sensitive data (company, customer, user, etc.), app authentication and encryption procedures must be used.
  • App verification requires Apple to log in to the customized app to test its functionality. A generic test account is sufficient.

Assign customized app Apple School/Business Manager account

Assign the customized app to the Apple School Manager, or Apple Business Manager account:

  1. in the logged in App Store Connect (as Account Holder, App Manager or as Admin) click on My Apps
  2. Select the customized app
  3. click on Prices and Availability in the side menu
  4. under App Distribution Methods select Private
  5. Under Type enter the organization ID of the Apple School Manager or Apple Business Manager account. If the old VPP (Legacy Volume Purchase Program) is still used, the app will be assigned via its Volume Purchasing Apple ID.
  6. Auf Speichern klicken

The thus assigned customized app will be displayed and distributed in the Apps and Books section of the Apple School Manager, or Apple Business Manager account.

Assign Apple School/Business Manager account to MDM portal

A connection to the Apple VPP (Volume Purchase Program) must be established. This is used to assign the customized app to the Apple School Manager or Apple Business Manager account.
MS v1.8 VPP upload-en.png
The connection is done in three steps at  Mobile Security Settings in section Apple VPP / Apple business Manager / Apple Schoolmanager with button  Add resp.  Update
  1. Download the Apple Push certificate (*.pem file)
  2. Upload this certificate in the [business.apple.com Apple Business Manager] or [school.apple.com Apple School Manager]
    This is only required once per location.
  3. Download the vpp token in the Apple Business Manager or Apple School Manager:
    • Klick on Username in the corner down left
    • Menü ABM Settings-Icon.png Settings
    •  Payments and Billing
    • Tab Apps and Books / Section Server-Tokens
    • ABM Server-Tokens.png Choose Token and Download
  4. Download the *.vpptoken file in the Securepoint Unified Security Portal under  Mobile Security Preferences
    in the section Upload Apple VPP / Apple Business Manager / Apple School Manager
    using the buttons  Add or  Update /  Upload Token.
    Finish with  Done
VPP tokens expire annually and must therefore be renewed regularly

More information about VPP can be found in the wiki article Connecting to Apple's VPP.

Assign customized app to MDM portal

Under  Mobile Security iOS/iPadOS  Apps , clicking the  Add app button adds the customized app to the MDM portal.
This app is configured as follows:

Caption Value Description MS 1.13 iOS Apps Angepasste-App-en.png
Type App Select the type App
Name Name Enter the name for the app
Source Customized App ID Customized App ID must be selected as the app source.
iTunes Store ID iTunes Store ID Enter the iTunes Store ID of the customized app
Take management    Activate management take over
Purchase method Unspecified Select purchase method
Management flags: Both deactivated Select Management flags
Devices »Add device Add the devices that should have access to the customized app
User »Add user Add the users who should have access to the customized app
Roles »Add roles Add the roles that should have access to the customized app
Tags »Add tags Add the tags that should have access to the customized app
Comment Comment A comment can be added
After the configuration has been performed, this pop-up window appears with the app installation of the sample app Speedtest.

After clicking the   Save button, the customized app will be deployed to the selected iOS devices, users, roles or tags.
Alternatively, the button /  Install performs the installation and accompanying distribution.



Installing an app that is not listed

Requirement of unlisted apps

In order for an unlisted app to be distributed, it must

  • Be present in the app store, or in final deployment and submitted for the app review process; and
  • a note be added to the app review that the app should be deployed as unlisted, and
  • a request be made in English to deploy as a non-listed app.

A link will be generated. This will allow the app to be accessed in the App Store and Apple Business Manager or Apple School Manager.
Here is additional information about unlisted apps on iOS devices.

The unlisted app is provided on the MDM portal and managed via it. Access must be available.

Set up unlisted app in App Store

If the app is not yet set up in the App Store, this is done with the following steps:

  1. Log in to App Store Connect as Account Holder, App Manager or as Admin.
  2. in My Apps click on the button Add (+)
  3. In the pop-up window, click New App
  4. in New-App-Dialog select the platforms iOS and enter the app information
  5. select User Access Limited Access and select the Apple School Manager or Apple Business Manager account.
  6. Click on Create

This app, which will become the unlisted app, must either be  Ready as status, or submitted in final deployment for app review.
In the app check, add a note that this app should be deployed as an unlisted app.
Then send a request to deploy as unlisted app.

The request will be rejected if the app has not been sent for app review, or if it is a beta or pre-release version.

If an app is privately provided via Apple School Manager or Apple Business Manager account and this app is to become an unlisted app, then:

  1. create a new app entry in App Store Connect
  2. Upload IPA file of this app and select Public as Deployment Method
  3. Create a request as an unlisted app


After the request is approved, the app is available as an unlisted app.

Assign the unlisted App Apple School/Business Manager Account

The unlisted app is assigned to the Apple School Manager, or Apple Business Manager account:

  1. in the logged in App Store Connect (as Account Holder, App Manager or as Admin) click on My Apps
  2. Select the app that is not listed
  3. click on Unlisted App in the side menu (changed from Prices and Availability)
  4. under App Distribution Methods select public
  5. a link is generated, through which users can access the app in the Apple School Manager, respectively Apple Business Manager

Assign Apple School/Business Manager account to MDM portal

A connection to the Apple VPP (Volume Purchase Program) must be established. This will assign the unlisted app to the Apple School Manager or Apple Business Manager account.
MS v1.8 VPP upload-en.png
The connection is done in three steps at  Mobile Security Settings in section Apple VPP / Apple business Manager / Apple Schoolmanager with button  Add resp.  Update
  1. Download the Apple Push certificate (*.pem file)
  2. Upload this certificate in the [business.apple.com Apple Business Manager] or [school.apple.com Apple School Manager]
    This is only required once per location.
  3. Download the vpp token in the Apple Business Manager or Apple School Manager:
    • Klick on Username in the corner down left
    • Menü ABM Settings-Icon.png Settings
    •  Payments and Billing
    • Tab Apps and Books / Section Server-Tokens
    • ABM Server-Tokens.png Choose Token and Download
  4. Download the *.vpptoken file in the Securepoint Unified Security Portal under  Mobile Security Preferences
    in the section Upload Apple VPP / Apple Business Manager / Apple School Manager
    using the buttons  Add or  Update /  Upload Token.
    Finish with  Done
VPP tokens expire annually and must therefore be renewed regularly

More information about VPP can be found in the wiki article Connecting to Apple's VPP.

Assign unlisted app to MDM portal

If the unlisted app is not already in the MDM portal, it is added under  Mobile Security iOS/iPadOS  Apps using the  Add app button.
This app is configured as follows:

Caption Value Description MS 1.13 iOS Apps nicht-gelistete-App-en.png
Type App Select the type App
Name Name Enter the name for the app
Source Manifest URL Select Manifest URL as app source
Manifest URL Manifest URL Enter the URL/link of the unlisted app (see requirements).
Take management    Activate management take over
Purchase method Unspecified Select purchase method
Management flags: Both deactivated Select Management flags
Devices »Add device Add the devices that should have access to the unlisted app
User »Add user Add the users who should have access to the unlisted app
Roles »Add roles Add the roles that should have access to the unlisted app
Tags »Add tags Add the tags that should have access to the unlisted app
Comment Comment A comment can be added
After the configuration has been performed, this pop-up window appears with the app installation of the sample app Speedtest.

After clicking the   Save button, the unlisted app will be distributed to the selected iOS devices, users, roles or tags.
Alternatively, the button /  Install performs the installation and accompanying distribution.