IntuneTroubleshooting

iOS/iPadOS apps not installing from Intune: VPP tokens, licences and installs stuck pending

Apple Business Manager apps assigned in Intune stay pending or fail on iPhones and iPads. How location (VPP) tokens and licences work, what the 0x87D13B error codes mean, and what to check in order.

You bought an app in Apple Business Manager, it appears in Intune, you assign it, and on the iPhone nothing happens: the device record shows the app pending for hours, or it flips to Failed with a 0x87D13B code. In this post I'll explain the chain Intune and Apple go through to get a volume-purchased app onto a device, where that chain usually breaks (token, licence, assignment, device), and how to read the error codes so you fix the right link.

How this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it. 4. Verify the fix. 5. Prevent it next time. Toolbox: 0x87D1313D, 0x87D13B95, 0x87D13B7E, Apps › All apps, 0x87D13B.1Symptoms2Why it happens3How to fix it4Verify the fix5Prevent it nexttimeTOOLBOX0x87D1313D0x87D13B950x87D13B7EApps › All apps0x87D13BHow this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it. 4. Verify the fix. 5. Prevent it next time. Toolbox: 0x87D1313D, 0x87D13B95, 0x87D13B7E, Apps › All apps, 0x87D13B.1Symptoms2Why it happens3How to fix it4Verify the fix5Prevent it next timeTOOLBOX0x87D1313D0x87D13B950x87D13B7EApps › All apps0x87D13B
At a glance: how this guide is organised · 5 sections · 5 key tools

Symptoms#

  • On the device record under Managed Apps, the app sits in a pending install state long after the device has synced, or shows Failed with a code such as 0x87D1313D, 0x87D13B95 or 0x87D13B7E.
  • Required apps install on some devices but not others, often the newest ones; available apps are missing from the Company Portal.
  • Users on corporate devices are suddenly prompted to sign in to the App Store or to accept an Apple Business Manager invitation.
  • Under Tenant administration › Connectors and tokens › Apple VPP tokens, the token shows Invalid, Expired or Duplicate, or its last sync is old.

Why it happens#

Intune doesn't install Apple apps. It tells Apple which licence from your location token to assign to which device or user, then sends an install command; the download itself happens between Apple and the device. For an install to succeed, every link has to hold:

  1. The token. A location token (what we used to call a VPP token) is valid for one year, belongs to one MDM and one Intune tenant at a time, and is synced with Apple once a day by default. Intune marks it Invalid when it expires or when the Managed Apple Account that created it changes, has its password expire, or is disabled. Uploading the same location token twice gives you Duplicate, and a duplicate token stops syncing. Importing a token that's already in Intune into another MDM can destroy licence assignments. The token's country/region setting decides which App Store the app metadata comes from.
  2. The licence. Apps can be device licensed (one licence per device, no Apple Account needed, installs and updates only through MDM) or user licensed (one licence covers up to five devices with the same personal Apple Account, requires an App Store sign-in and the Apple Business Manager invitation, and doesn't work if your configuration blocks the App Store). New assignments default to device licensing. Books and account-driven User Enrollment need user licensing. Assigning both licence types to the same device or user isn't supported.
  3. The assignment. Required installs silently where the device allows it; Available only works with user groups and the app isn't managed until the user installs it from the Company Portal. Tokens set to the DDM management type don't support Available at all. If you oversubscribe, the first members get licences and the rest fail licence assignment.
  4. The device. Supervised devices with device-licensed apps install with no prompts. Unsupervised devices show an install prompt the user must accept. Devices in Lost Mode or kiosk mode, locked devices, and devices with the App Store disabled all refuse installs, and updates wait until the device is unlocked.

Note: Removing an app's assignment doesn't give the licence back. Intune reclaims a licence when you change the assignment to Uninstall, when you use Revoke license after removing the assignment, or when the user is deleted from Entra ID. A user deleting the app from the home screen changes nothing on the licence side.

How to fix it#

  1. Check the token first. Go to Tenant administration › Connectors and tokens › Apple VPP tokens and look at status, expiry and last sync. Select Sync and wait for it to finish. If the token is invalid or expired, download a fresh token from Apple Business Manager under Preferences › Payments and Billing › Apps and Books › Content Tokens, open the token in Intune, select Edit on Basics and upload it. The expiry date in Intune can take a while to refresh after a renewal. If you see Duplicate, remove the extra copy. If the token came from another MDM, re-upload with Take control of token from another MDM set to Yes.
  2. Check licence counts. Open Apps › All apps, select the app and look at App licenses. If used equals total, buy more in Apple Business Manager or reclaim licences from users and devices that no longer need them. Counts update within a few hours of an install or uninstall, so don't expect an instant change.
  3. Check the assignment. Confirm the intent, the group type (Available needs user groups), the licence type on the assignment, and that any app configuration policy the app depends on is targeted to the same groups. For corporate devices, prefer device licensing so nobody is asked for an Apple Account.
  4. Read the error code on the device's Managed Apps page or in Troubleshooting + support › Troubleshoot for the user, and act on it:
    CodeMicrosoft's descriptionWhat to do
    0x87D1313DCould not retrieve license for the app with iTunes Store IDSync the token, then sync the device; if it persists, reassign as device licensed, or revoke the licence from the device and reassign
    0x87D13B7ELicense assignment failed: No VPP licenses remainingBuy more licences or reclaim unused ones
    0x87D13B95Can't find VPP license for appRevoke and reassign the app licence
    0x87D13B7DUnknown error; one documented cause is an expired tokenVerify the token is current and functional
    0x87D13B99User must sign in to the App StoreUser-licensed app: have the user sign in, or switch to device licensing
    0x87D13B94Can't install apps when App Store is disabledAllow the App Store, or use device licensing on supervised devices
    0x87D11388Device is busy (locked)Ask the user to unlock the device and sync
    0x87D13BA9Device licensing isn't supported on account-driven User Enrollment devicesCreate a user-licensed assignment for those users
  5. Check the device itself. Make sure it's unlocked, online and not in Lost Mode or a kiosk profile, then select Sync on the device record and watch Managed Apps change.
  6. For user-licensed apps, finish the Apple side. The user must accept the Apple Business Manager invitation when it's offered and sign in to the App Store with their own Apple Account; until both happen, licence assignment can't complete. If that's not acceptable for your corporate fleet, move the assignment to device licensing; Intune can migrate silently from user to device licences only for Required assignments.
  7. Collect Company Portal logs if you're still stuck. In the Company Portal app, open the More tab and tap Send Logs, or shake the device and tap Send Diagnostic Report, or tap Report on the error itself. Note the incident ID and use Email Logs to send it to your helpdesk; Microsoft Support can pull the upload by that ID.

Watch out: Deleting a token deletes every app and assignment tied to it and revokes their licences, but it doesn't uninstall anything from devices, and Intune can't revoke licences for a token that no longer exists. Renew or edit the token instead of deleting it unless you're cleaning up a genuine duplicate.

Verify the fix#

  • The token shows a valid status, a fresh last-sync time and an expiry a year out.
  • The app's App licenses page shows one more used licence per device or user that just got it.
  • On the device record, Managed Apps shows the app as installed, and the icon is on the home screen without a Store prompt (device licensing) or after a single sign-in (user licensing).
  • A newly enrolled device in the same group gets the app on its first check-in without anyone touching the admin center.

Prevent it next time#

  • Put the three Apple renewals on one calendar: the MDM push certificate, the Automated Device Enrollment token and every location token. All expire after a year, and a lapsed token looks exactly like a mysterious install failure.
  • Keep one location token per location, in one Intune tenant, uploaded once, and never share it with another MDM.
  • Standardize on device licensing for corporate, supervised devices; keep user licensing for BYOD and User Enrollment, where an Apple Account is expected anyway.
  • Check licence usage before assigning to a bigger group; Intune raises an alert once an app's used licences reach half of the total.
  • Moving to DDM management? Use a new token: re-uploading an existing one with available assignments drops those assignments.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)