You bought an app in Apple Business Manager, it appears in Intune, you assign it, and on the iPhone nothing happens: the device record shows the app pending for hours, or it flips to Failed with a 0x87D13B code. In this post I'll explain the chain Intune and Apple go through to get a volume-purchased app onto a device, where that chain usually breaks (token, licence, assignment, device), and how to read the error codes so you fix the right link.
Symptoms#
- On the device record under Managed Apps, the app sits in a pending install state long after the device has synced, or shows Failed with a code such as
0x87D1313D,0x87D13B95or0x87D13B7E. - Required apps install on some devices but not others, often the newest ones; available apps are missing from the Company Portal.
- Users on corporate devices are suddenly prompted to sign in to the App Store or to accept an Apple Business Manager invitation.
- Under Tenant administration › Connectors and tokens › Apple VPP tokens, the token shows Invalid, Expired or Duplicate, or its last sync is old.
Why it happens#
Intune doesn't install Apple apps. It tells Apple which licence from your location token to assign to which device or user, then sends an install command; the download itself happens between Apple and the device. For an install to succeed, every link has to hold:
- The token. A location token (what we used to call a VPP token) is valid for one year, belongs to one MDM and one Intune tenant at a time, and is synced with Apple once a day by default. Intune marks it Invalid when it expires or when the Managed Apple Account that created it changes, has its password expire, or is disabled. Uploading the same location token twice gives you Duplicate, and a duplicate token stops syncing. Importing a token that's already in Intune into another MDM can destroy licence assignments. The token's country/region setting decides which App Store the app metadata comes from.
- The licence. Apps can be device licensed (one licence per device, no Apple Account needed, installs and updates only through MDM) or user licensed (one licence covers up to five devices with the same personal Apple Account, requires an App Store sign-in and the Apple Business Manager invitation, and doesn't work if your configuration blocks the App Store). New assignments default to device licensing. Books and account-driven User Enrollment need user licensing. Assigning both licence types to the same device or user isn't supported.
- The assignment. Required installs silently where the device allows it; Available only works with user groups and the app isn't managed until the user installs it from the Company Portal. Tokens set to the DDM management type don't support Available at all. If you oversubscribe, the first members get licences and the rest fail licence assignment.
- The device. Supervised devices with device-licensed apps install with no prompts. Unsupervised devices show an install prompt the user must accept. Devices in Lost Mode or kiosk mode, locked devices, and devices with the App Store disabled all refuse installs, and updates wait until the device is unlocked.
Note: Removing an app's assignment doesn't give the licence back. Intune reclaims a licence when you change the assignment to Uninstall, when you use Revoke license after removing the assignment, or when the user is deleted from Entra ID. A user deleting the app from the home screen changes nothing on the licence side.
How to fix it#
- Check the token first. Go to Tenant administration › Connectors and tokens › Apple VPP tokens and look at status, expiry and last sync. Select Sync and wait for it to finish. If the token is invalid or expired, download a fresh token from Apple Business Manager under Preferences › Payments and Billing › Apps and Books › Content Tokens, open the token in Intune, select Edit on Basics and upload it. The expiry date in Intune can take a while to refresh after a renewal. If you see Duplicate, remove the extra copy. If the token came from another MDM, re-upload with Take control of token from another MDM set to Yes.
- Check licence counts. Open Apps › All apps, select the app and look at App licenses. If used equals total, buy more in Apple Business Manager or reclaim licences from users and devices that no longer need them. Counts update within a few hours of an install or uninstall, so don't expect an instant change.
- Check the assignment. Confirm the intent, the group type (Available needs user groups), the licence type on the assignment, and that any app configuration policy the app depends on is targeted to the same groups. For corporate devices, prefer device licensing so nobody is asked for an Apple Account.
- Read the error code on the device's Managed Apps page or in Troubleshooting + support › Troubleshoot for the user, and act on it:
Code Microsoft's description What to do 0x87D1313DCould not retrieve license for the app with iTunes Store ID Sync the token, then sync the device; if it persists, reassign as device licensed, or revoke the licence from the device and reassign 0x87D13B7ELicense assignment failed: No VPP licenses remaining Buy more licences or reclaim unused ones 0x87D13B95Can't find VPP license for app Revoke and reassign the app licence 0x87D13B7DUnknown error; one documented cause is an expired token Verify the token is current and functional 0x87D13B99User must sign in to the App Store User-licensed app: have the user sign in, or switch to device licensing 0x87D13B94Can't install apps when App Store is disabled Allow the App Store, or use device licensing on supervised devices 0x87D11388Device is busy (locked) Ask the user to unlock the device and sync 0x87D13BA9Device licensing isn't supported on account-driven User Enrollment devices Create a user-licensed assignment for those users - Check the device itself. Make sure it's unlocked, online and not in Lost Mode or a kiosk profile, then select Sync on the device record and watch Managed Apps change.
- For user-licensed apps, finish the Apple side. The user must accept the Apple Business Manager invitation when it's offered and sign in to the App Store with their own Apple Account; until both happen, licence assignment can't complete. If that's not acceptable for your corporate fleet, move the assignment to device licensing; Intune can migrate silently from user to device licences only for Required assignments.
- Collect Company Portal logs if you're still stuck. In the Company Portal app, open the More tab and tap Send Logs, or shake the device and tap Send Diagnostic Report, or tap Report on the error itself. Note the incident ID and use Email Logs to send it to your helpdesk; Microsoft Support can pull the upload by that ID.
Watch out: Deleting a token deletes every app and assignment tied to it and revokes their licences, but it doesn't uninstall anything from devices, and Intune can't revoke licences for a token that no longer exists. Renew or edit the token instead of deleting it unless you're cleaning up a genuine duplicate.
Verify the fix#
- The token shows a valid status, a fresh last-sync time and an expiry a year out.
- The app's App licenses page shows one more used licence per device or user that just got it.
- On the device record, Managed Apps shows the app as installed, and the icon is on the home screen without a Store prompt (device licensing) or after a single sign-in (user licensing).
- A newly enrolled device in the same group gets the app on its first check-in without anyone touching the admin center.
Prevent it next time#
- Put the three Apple renewals on one calendar: the MDM push certificate, the Automated Device Enrollment token and every location token. All expire after a year, and a lapsed token looks exactly like a mysterious install failure.
- Keep one location token per location, in one Intune tenant, uploaded once, and never share it with another MDM.
- Standardize on device licensing for corporate, supervised devices; keep user licensing for BYOD and User Enrollment, where an Apple Account is expected anyway.
- Check licence usage before assigning to a bigger group; Intune raises an alert once an app's used licences reach half of the total.
- Moving to DDM management? Use a new token: re-uploading an existing one with available assignments drops those assignments.