App deployment and management

App Installation w/ Apple Apps and Books

Overview


Remotely installing and updating apps is a critical task when managing devices. For this reason, Mosyle supports the installation of apps using managed distribution to devices and/or users. The Install App profile under the Management tab provides the ability to install, reinstall, update, and configure apps in bulk.

Once Install App profiles are created in the account, Administrators can search and filter the profiles based on the profile name and/or category.

As a reminder, the Mosyle Manager application is available for devices enrolled via Automated Device Enrollment and Device Enrollment and provides Administrators with the ability to allow users to complete the installation of apps, web clips, profiles, and more.

To automatically install the Mosyle Manager app so users can access Self-Service on iOS/iPadOS devices, first obtain licenses for the app in Apple School Manager. Once licenses are available and the Apps and Books token is integrated, go to Management > Install App (iOS/iPadOS) > Click Edit Configuration for the Mosyle Manager App Installation profile. Choose the Apps and Books token to use for licensing and click Save.

automatic-installation.png

 

 

The Manager.app along with the Mosyle agent is automatically installed on macOS devices enrolled using Automated Device Enrollment and Device Enrollment. If needed, it can be reinstalled on devices using the command in Management > Devices Overview > Resend Manager agent.

resend.png

 

 

 

Installation Source & License Assignment


To install apps, go to Management > Install App.

Install App profiles can be created to install a single app or groups of apps, to multiple groupings of users and devices. When creating a new configuration profile, name the profile and select the installation source which indicates the source of the app license. For apps available in the App Store, including free apps, it's recommended to obtain licenses using Apple School Manager so they can be deployed using the Apple Apps and Books (VPP) token as the installation source. Similarly, to deploy Custom Apps available in a school or district's Apple School Manager account, choose Apple Apps and Books (VPP) token as the installation source.

*Choosing the App Store as the installation source for iOS or iPadOS devices will result in users being prompted to enter a personal/consumer Apple ID in order to download/install the assigned applications.

After selecting the installation source as Apple Apps and Books (VPP), choose the method in which the license for the app will be assigned. Choosing a device-based license assignment (recommended) will assign the app license to the device serial number, allowing the installation process to be silent to the end user, requiring no user interaction.

Tip: When enrolling via User Enrollment, user-based license assignment is required. This type of license assignment will assign the app license to the user's Apple ID and requires users to be registered in Mosyle with a valid Managed Apple ID and an invite to be associated with the user (Management > Applications > Apple Apps and Books > Invites). The same Apple ID that is associated with the invite must be logged in on the device.

Next, choose the app or apps to be installed and select the users, devices, and/or device groups to assign the profile to in the Profile Assignment area.

image.png

 

 

 

Installation Options


Additional options can be configured when creating an Install App profile in Mosyle. These additional options provide Administrators the ability to control whether apps are automatically installed, available in Self-Service, updated automatically, and/or removed when the assignment is removed.

 

Managing App Updates


The Install App profile can be configured to automatically update apps. Mosyle regularly scans the App Store for updated versions of apps. If an updated version is detected, commands to update the apps can be sent automatically. There are multiple options regarding app updates to choose from:

Requests to update apps can also be pushed from the App Center, Devices Overview/Device Information, or using the Single Shot profile. The Single Shot profile provides the ability to configure a schedule for when the commands for app updates will be sent.

Notes:

 

Managing the Removal of Apps


The Install App profile can be configured to automatically remove applications no longer assigned to iOS/iPadOS devices in the profile. Choose between the following options:

Managed apps can also be removed from devices under Devices Overview and in the App Center. If the apps are not yet managed by the MDM, the user will be prompted to enter their Apple ID and password to first confirm management of the app before the app can be removed by the MDM.

 

 

Managed App Configuration (iOS/iPadOS)


App Configuration is supported by devices running iOS 7 or later and is available in the Install App profile, allowing you to send custom configurations supported by the app developers to applications. Some examples include configuring a specific license or key code for an application. Hover an app in the profile to show the 'C' button in the bottom corner and then click on it to open the App Configuration window. Check the box for “Prepare and Apply an AppConfig PLIST”. If the app's software developer has provided keys and values for the configuration, or an XML file, paste the contents starting with and ending with . When finished, click Confirm.

app-configuration.png

 

 

Installation Flow & Status


Once an Install App profile is created and assigned to users/devices, the View Details area will display the installation status of the apps. There are multiple steps to the installation process for apps, starting with the license assignment. Because of this, it's important to understand the flow in which apps are installed on devices via the MDM.

Before commands to install an application are sent to the device, the MDM first assigns the app license to the device. Once the app license assignment is confirmed to be successful, the MDM generates and sends the command to install the app to the device. The device then validates the app license with Apple servers and proceeds to fetch the app file from the App Store or from a local network caching server. The diagram below gives a broad overview of this flow.

flow.png

Note: This flow is specific for installing apps using device-based license assignment.

The View Details area of the Install App profile provides insight into the status of the app installation process. The app installation status will display if the command is pending or failed, any errors occurred, the app is downloading/installing, installed, outdated, removed, or available in Self-Service.

status.png

Important Notes:

Visit Apple's documentation regarding Content Distribution with MDM for more information.

 

Enterprise App Installation

Overview


Mosyle supports the installation of proprietary in-house apps on iOS and iPadOS devices through the Install Enterprise profile. The installation of Enterprise apps requires self-hosting, or hosting via Mosyle's CDN, as well as the management of provisioning profiles and distribution certificates.

Reminder: Custom Apps available to organizations within their Apple School Manager account can be deployed using the Install App profile and choosing the Apple Apps and Books (VPP) token as the installation source.

 

 

Adding Enterprise Apps


To install proprietary in-house apps on iOS and iPadOS devices, go to Management > Install Enterprise.

Before creating the Install Enterprise profile, the .ipa file must be hosted and publicly accessible, requiring no user interaction to download. Once hosted, click the Enterprise Apps tab > Add new Enterprise App and enter the .ipa file URL. After entering the URL, Mosyle will automatically retrieve the app name, bundle identifier, and version information. An app icon can be uploaded to the Mosyle console for easy identification of the app within the console and Self-Service.

adding.png

Mosyle provides its own private cloud hosting solution that allows you to host packages directly in the MDM. If the account has access to the Mosyle CDN, simply upload the .ipa file under the Enterprise apps tab to create the app.

 

 

Creating Install Enterprise app profile


After Enterprise Apps are created in Mosyle, click the Profiles tab > Add new profile. Name the profile and select any of the Enterprise apps available in the account to be installed on the devices.

Similar to the Install App profile, options are available for auto-installation, whether the app will be available in Self-Service, as well as uninstall, reinstall, and update behavior.

 

Updating Enterprise Apps


To deploy updates to Enterprise apps, the .ipa file URL for the updated version will need to be added to Mosyle. Once added, the Install Enterprise profile will need to be updated to include the new version. The old version can be deleted from Mosyle under Management > Install Enterprise > Enterprise Apps, click on the previous version of the app and then click Delete in the bottom-right corner of the profile (optional).

After the new version is added to the profile, if the profile is configured to update apps automatically, upon saving the profile commands will be generated to install and update the app on the devices.

Note: Mosyle uses version comparison to determine if an app is outdated. Be sure the value of any new app versions are greater than the current version.

 

Managing the Removal of Enterprise Apps


Enterprise apps can be automatically uninstalled when the Install Enterprise profile is edited using the Advanced Options in the profile.

Managed Enterprise apps can also be removed from devices via Devices Overview and the App Center.

 

Installation Status


Once an Install Enterprise profile is created and assigned to users/devices, the View Details area will display the installation status of the app.

Mosyle Catalog App Installation

Overview


Mosyle Catalog provides the ability to install, update, and manage third party applications that are not available in the Mac App Store, without having to manually download and host PKG or DMG files. Installing apps using Mosyle Catalog can also automatically install any additional permissions needed for the app, such as Privacy Permissions, System Extensions, or Kernel Extensions.

Whenever available, the Universal version of the application will be installed through the Mosyle Catalog. If a Universal version of the app is not available, the appropriate version of the app will be installed on compatible devices - Apple silicon versions of the app will be installed on Apple silicon devices, and Intel versions of the app will be installed on Intel devices. If only the Intel version of the app is available by the app developer, then the Intel version of the app will be installed on devices. In this scenario, it's recommended that Rosetta 2 is installed on Apple silicon devices.

Apps added to the Mosyle Catalog are based on customer requests. All apps offered in the Mosyle app catalog are owned, distributed, and maintained by each respective software developer. When sending installation commands, Mosyle uses direct download links provided by each respective software developer, thus all packages are offered as-is, without warranty, and the functionality, compatibility, and/or availability of each package cannot be guaranteed by Mosyle. Any licensing or rights to the third party software packages is not offered by Mosyle.

The installation of apps using the Mosyle Catalog requires the Mosyle Manager app to be installed on the Macs. Installation of apps using the Mosyle Catalog is not supported on User Enrolled devices.

 

Creating Install App profile using Mosyle Catalog


To install macOS apps using the Mosyle Catalog, go to Management > Install App > Add new Profile > Choose the installation source “Mosyle Catalog”.

To view the list of applications available in Mosyle Catalog, click the “+ Add Application” button. Within this area, all applications available to be installed are listed along with any permissions required. To view the permissions required for the app, click the link “View permissions for this app”. If you prefer to manually manage the permissions by creating the required management profiles, uncheck the box for “Automatically grant permissions required”.

permissions.png

Choose the app or apps to be installed and select the users, grade levels, devices, and/or groups to assign the profile to in the Profile Assignment area.

apps.png

 

 

Installation Options


Similar to installing apps from Apple Apps and Books, additional options can be configured when creating an Install App profile in Mosyle.

Administrators can control whether apps are automatically installed or available in Self-Service. If choosing the option to “Do not install all apps after saving the profile”, it's recommended to use the option to “Show the apps in Self-Service” so that users can manually request the installation of the apps as needed.

If the option is selected to “Install all apps after saving the profile”, apps will be immediately installed after enrollment if the device is assigned to a User, Grade Level, Course/Class Period, Shared Device Group, or Dynamic Device Group that is assigned to the Install App profile. Administrators can also choose whether apps that have been manually removed should be automatically reinstalled under “Show advanced options”.

 

Updating Apps in Mosyle Catalog


The Install App profile with Mosyle Catalog can be configured to automatically update apps without having to manually update and host the PKG and DMG. Mosyle scans for updated versions of the apps every 24 hours. If an updated version is detected, commands to update the apps can be sent automatically. There are multiple options regarding app updates to choose from:

Requests to update apps can also be pushed from Device Information, by clicking the paper airplane option to install/update the app, or requested using Self-Service.

 

Managing the Removal of Mosyle Catalog Apps


Mosyle Catalog apps can be automatically uninstalled when the Install App profile is edited using the Advanced Options in the profile. To configure the profile so that applications are automatically removed when they are no longer assigned to devices in the profile use one of the following options:

 

Installation Status


Once an Install App profile is created and assigned to users/devices, the View Details area will display the installation status of the app.

 

 

Install PKG

Overview


Mosyle supports the installation of applications not available in the App Store on macOS devices through the Install PKG profile. The installation of these apps require the PKG, DMG, or ZIP file to be hosted so that they are publicly accessible and directly downloadable without redirection and/or user interaction. They can be self-hosted on a local server (such as SMB), third party CDN, or hosted using Mosyle's CDN.

Despite only specifying “PKG” in the profile name, Mosyle supports the deployment of apps from PKGs, DMGs, and/or ZIP files. The PKG must be a flat PKG. It's recommended each PKG only contain a single application.

 

Adding PKGs


To install PKGs on macOS devices, go to Management > Install PKG.

Before creating the Install PKG profile, the PKG, DMG, or ZIP file used to install the application must be created, hosted, and publicly accessible, requiring no user interaction to download. Many app developers provide a PKG, DMG, or ZIP file that can be hosted and used to remotely deploy the app to multiple devices. If the file is not provided, you can generate the PKG for the app using the Mosyle Manager app (PKGs tab > Add new package > Generate .PKG with Mosyle Manager).

After generating or obtaining the PKG file, it must be hosted so that devices can access and retrieve the file to complete the installation. Mosyle provides its own private cloud hosting solution that allows you to host packages directly in the MDM. If the account has access to the Mosyle CDN, upload the PKG, DMG, or ZIP file under the CDN tab to host.

Once hosted, click the PKGs tab > Add new package > Already have a .PKG.

adding.png

Choose from the following options to configure the app information, which is used to track installation status and if the app is outdated or not:

When editing or manually entering the app information for the PKG, the following fields are available:

Once all app information has been entered, click Save.

 

Creating Install PKG profile


After the PKGs are created in Mosyle, click the Profiles tab > Add new profile. Name the profile and select any of the PKGs available in the account to be installed on the devices.

If the app is signed and it is being installed on User Enrolled devices, check the box to “Install with Apple Protocol”. This will use the MDM protocol command to install the PKG rather than using the Mosyle agent. Keep in mind, PKGs installed using MDM protocol must contain a single, signed application installed into /Applications. If the app is being installed on devices enrolled using Automated Device Enrollment or Device Enrollment, it's recommended to leave this option unchecked.

Options are available for auto-installation, delayed installation, and whether the app will be available in Self-Service.

 

Managing Updates with Install PKG


To deploy updates to apps installed via Install PKG, a new PKG must be created and hosted with the new app version and added to Mosyle. Be sure to update the version field when adding the updated PKG. Once added, the Install PKG profile will need to be updated to select the new/updated version. The old version can be deleted from Mosyle under Management > Install PKG > PKGs, click on the previous version of the app and then click Delete in the bottom-right corner of the profile (optional).

After the new version is added to the profile, if the profile is configured to update apps automatically, upon saving the profile commands will be generated to install and update the app on the devices.

Note: Mosyle uses version comparison to determine if an app is outdated. Be sure the value of any new app versions are greater than the current version.

 

Managing the Removal of Apps


Some apps installed using the Install PKG profile on devices running macOS Big Sur or later can be considered "managed" and therefore, can be removed using an MDM command. In order for an enterprise app (PKG) to be considered a managed app on macOS, it has to meet certain criteria:

If the app is managed, it can be removed through Device Info under the Apps tab. If the app is not a managed app, or the device is not running macOS Big Sur or later, you can remove the app from the Mac using the uninstaller provided by the app developer, or a custom command such as: rm -rf /Applications/PATH_TO_APP.app

 

Custom Configuration of PKGs


Applications that require specific configurations, such as a registration code or license key, can be installed on devices using the Install PKG profile. When creating the PKG in Mosyle, enter the configurations necessary as a pre- or post-install script so that they are applied either before or after the installation of the app. Check the app developer documentation for more information on any configuration specifications.

custom-config.png

If preferred, the installation of applications with specific configurations can also be done using the Custom Commands.

 

Installation Status


Once an Install PKG profile is created and assigned to users/devices, the View Details area will display the installation status of the app. The verification that the app has been installed relies on the bundle ID entered when creating the PKG in Mosyle. If the bundle ID for the app is incorrect, the installation status will remain as “Installing” or “Removed” due to Mosyle being unable to match the bundle ID of the PKG with a bundle ID of an app installed on the device.

 

App Center

Overview


The App Center itemizes all apps installed on managed devices based on platform (iOS / iPadOS, macOS, tvOS). It includes detailed information about an app's name, bundle identifier, category, status, how many devices it's installed on, and if it's managed (iOS / iPadOS).To access the App Center, go to Management > Applications > App Center.

Filter the apps by clicking Add Filter at the top of the screen. Filter the list using the Filter options along the top, or enter search criteria to find a specific device or app. The information provided by the filters is also designed to be sorted with a simple click of a column name or edited with a click of the search.

Commands available along the toolbar of the App Center include:

Notes: Manage Apps supports macOS devices running 11 or later. In order for an enterprise app to be manageable on macOS, it has to meet certain criteria: it must not contain any nested packages, it must contain only a single signed app, and it must be installed in /Applications.

 

 

Additional Information


Within the App Center you can see the Install app or Install PKG profiles the app is assigned to as well as the installation status of the app. Use the Filters to search for apps installed or not installed through profiles, installation source, managed status, and more.

Click the “View” link under the Profiles column to view the Install app or Install PKG profile associated with the app.

Click the “View” link under the Installed column to view the installation status of the app or PKG. The installation status should reflect the same information that is presented in the “View Details” area of the Install App profile.

app-center.png