Overview
Apple Business Manager became Apple Business in April 2026. The Volume Purchase Program was integrated years earlier, but many management platforms and support articles still use the terms VPP token, location token, server token, or sToken. In Apple's current terminology, the file used by an external device management service to communicate about app and book licenses is a content token.
A content-token problem affects communication about Apps and Books licenses and managed app assignments. It is separate from an Automated Device Enrollment token and the Apple Push Notification service certificate, even though all three may appear near one another in a device management console.
Where to download the current content token
- Open Apple Business. Sign in at business.apple.com with a Managed Apple Account whose role can obtain and assign Apps and Books licenses.
- Open the token area. In the browser interface, go to Settings > Payments & Billing, select Apps and Books, then download the content token for the intended external device management service or organizational unit.
- Match the license pool. Confirm the organizational unit—or legacy location name shown by an existing MDM integration—matches the app licenses and existing token record you intend to renew.
- Update the existing MDM record. Use the vendor's renewal or edit workflow to upload the downloaded token to the existing connector. Do not create a second connector merely because the file is new.
Before replacing or deleting anything
- Record the current state. Capture the token name, external management service, organizational unit or legacy location, expiration date, Managed Apple Account, last successful sync, current error, and affected applications.
- Preserve assignment evidence. Export or record app assignments and license counts where the management platform supports it. This is especially important before a management-service migration.
- Identify the failing integration. Confirm whether the alert concerns the Apps and Books content token, the Automated Device Enrollment token, or the Apple Push Notification service certificate. Renewing one does not repair the others.
- Avoid deleting the connector. Some MDM platforms associate applications, assignments, license state, and revocation capability with the existing token object. Renewal should update that object unless the vendor's documented migration procedure requires replacement.
Expired or invalid token
Apple states that content tokens become invalid one year after creation and when the password changes for the Managed Apple Account used to download the existing token. A management platform may also report the token as invalid after related account changes, such as a domain change, password expiration, or account disablement.
- Download a fresh token. Use an authorized Managed Apple Account to download the current content token for the same external management service and organizational unit or legacy location.
- Renew the existing connection. Upload the file through the existing token's edit or renewal workflow in the MDM console. For Microsoft Intune, update the existing Apple VPP token under Tenant administration > Connectors and tokens.
- Verify the result. Confirm the MDM console shows the new expiration date, run or wait for a content sync, and verify that expected applications and license counts return without recreating assignments.
- Use a dedicated account going forward. Apple recommends a dedicated Managed Apple Account with a custom role limited to the Apps and Books license permission for downloading and managing content tokens.
How to interpret authentication and vendor error messages
Error text varies by management platform. A generic HTTP 401 indicates an authentication failure, but it does not by itself distinguish an expired token, password-driven invalidation, a disabled account, a malformed upload, or a vendor-side connector problem. Numeric messages such as 9625 should be interpreted using the documentation for the MDM product that emitted them, not presented as universal Apple error codes.
- Check token and account state together. Compare the token expiration date with recent password, domain, role, and account-status changes for the Managed Apple Account associated with token management.
- Preserve the vendor message. Record the full error, timestamp, connector name, request or correlation identifier, and last successful synchronization before renewing.
- Escalate persistent authentication failures. If a fresh token uploaded to the existing connector remains invalid, use the MDM vendor's token troubleshooting path before deleting the connector or transferring licenses.
Token already used by another management service
A content token should not be used concurrently by multiple external management services or separate MDM tenants. Reusing it can create inconsistent license inventory, assignment failures, or loss of user and license records.
- Identify the active owner. Determine which production, test, regional, or legacy management service currently uses the token and which organizational unit or legacy location supplies its licenses.
- Plan a controlled migration. Follow both Apple's and the destination vendor's migration sequence. Record assignments, remove the token from the source at the planned cutover, upload the appropriate token to the destination, and verify license inventory before changing application assignments.
- Create separation at the license-pool level. If two management services must operate at the same time, use separate organizational units or legacy locations and intentionally transfer or acquire the required licenses for each pool. Do not reuse one token in both services.
Token uploads but applications do not sync
- Confirm licenses exist in the selected pool. Verify that the applications were acquired in Apps and Books and assigned to the organizational unit or legacy location represented by the content token. A valid but empty pool can synchronize successfully without displaying applications.
- Check synchronization behavior. Some MDM platforms synchronize automatically on a schedule and also provide a manual sync action. For example, Intune synchronizes location tokens daily by default and allows an administrator to start a manual sync.
- Verify the existing connector was renewed. If a second connector was accidentally created, the expected assignments may still belong to the original token record. Compare token identity, location or organizational unit, and assigned applications before moving anything.
- Review app availability and assignment. Confirm the application remains available in the relevant country or region, sufficient licenses exist, and the device or user assignment is still active in the MDM platform.
- Use vendor logs for the next step. If license inventory is correct but synchronization still fails, inspect the management platform's connector status and synchronization logs rather than repeatedly downloading new token files.
Symptom-based decision path
| Symptom | Check first | Safest next action |
|---|---|---|
| Token is expired or invalid | Expiration and Managed Apple Account changes | Download the matching token and update the existing connector |
| Authentication or 401 error | Full vendor error, account state, and token expiration | Renew in place; use vendor troubleshooting if it remains invalid |
| Token is already in use | Current MDM tenant or service using the token | Plan a controlled migration or separate the license pools |
| Upload succeeds but no apps appear | Organizational unit or legacy location and acquired licenses | Run a sync and verify the token represents the expected pool |
| Apps appear but assignments fail | Available license count and assignment state | Correct license or assignment state without replacing the token |
| Device enrollment fails | ADE token, APNs certificate, profile, and network path | Troubleshoot enrollment separately from the content token |
Before the next renewal cycle
- Assign durable ownership. Use a dedicated Managed Apple Account rather than a personal administrator account, document the account owner and recovery process, and grant only the permissions required to manage Apps and Books licenses.
- Track expiration independently. Record the token expiration in the team's operational calendar or monitoring system and create reminders early enough to renew and verify before the one-year deadline.
- Add account changes to the runbook. Require a content-token check after password, domain, role, or account-status changes affecting the Managed Apple Account used for token management.
- Test the full outcome. A successful upload is not enough. Verify the updated expiration, a completed catalog sync, expected license counts, and at least one representative managed-app assignment.
Related resources
- Plan the broader enrollment and management lifecycle with the Apple Business Manager rollout plan for security teams.
- Use the full endpoint lifecycle model in Zero-touch endpoint management for security teams.
- Explore Gideon Endpoint Management for managed app delivery and endpoint operations evaluation paths.
Primary references
- Apple documents current token validity, account-change behavior, least-privilege ownership, and the download path in Manage content tokens in Apple Business.
- Apple explains the 2026 product transition in Apple Business Manager is now Apple Business.
- Apple documents content-token handling during a service migration in Migrate devices to a new management service.
- Microsoft documents Intune renewal, synchronization, account changes, and token-reuse constraints in Manage Apple volume-purchased apps.
How to use this resource
Use this runbook when app licenses stop synchronizing, a token approaches expiration, or an MDM migration exposes a token conflict. Preserve the existing connector and assignment state, identify the exact token and license pool, renew in place when possible, and define success as a verified catalog sync with expected license counts and working assignments.