{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-339-renew-an-apple-app-location-token-without-replacing-its-intune-record/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-339-renew-an-apple-app-location-token-without-replacing-its-intune-record/",
        "slug": "dse-20260909-339-renew-an-apple-app-location-token-without-replacing-its-intune-record",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-339-renew-an-apple-app-location-token-without-replacing-its-intune-record/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-339-renew-an-apple-app-location-token-without-replacing-its-intune-record.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-339-renew-an-apple-app-location-token-without-replacing-its-intune-record/"
        },
        "title": "Renew an Apple app location token without replacing its Intune record",
        "summary": "How should an expiring Apple location token be renewed without discarding associated app assignments?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:17+00:00",
        "modified_at": "2026-09-10T01:40:03+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 1,
        "word_count": 215,
        "potentially_affected": "Use this procedure boundary for routine token renewal, not an unplanned migration between management systems. Identify the Apple location and the corresponding existing Intune token before obtaining replacement token material.",
        "dse_recommendation": "Make the renewal record point to the existing token object and its app associations.",
        "primary_source": {
            "name": "Manage Apple Volume-Purchased Apps - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/app-management/deployment/manage-vpp-apple",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft&#8217;s renewal procedure downloads a fresh Apple location token and updates the existing token in Intune. A location token is supported in only one Intune tenant and one device-management solution at a time. Deleting the token also removes its associated apps and assignments. The displayed expiration can take time to reflect a successful renewal. <a href=\"https://learn.microsoft.com/en-us/intune/app-management/deployment/manage-vpp-apple\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this procedure boundary for routine token renewal, not an unplanned migration between management systems. Identify the Apple location and the corresponding existing Intune token before obtaining replacement token material.</p>\n<h2>DSE recommendation</h2>\n<p>Make the renewal record point to the existing token object and its app associations. Have the administrator confirm the location with a second reviewer before upload, and protect the downloaded token through the organization&#8217;s credential-handling process. Do not delete and recreate the object merely because the expiration display has not refreshed. Escalate a genuine location or tenant mismatch as a separate migration decision.</p>\n<h2>Verification</h2>\n<p>Refresh the token view until the updated expiration is observable, then synchronize and compare the associated app and assignment inventory with the pre-renewal record. Validate a representative managed app workflow after renewal. Keep the token contents out of screenshots and tickets; retain object identifiers, dates observed, and the actual synchronization outcome instead.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/app-management/deployment/manage-vpp-apple\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Manage Apple Volume-Purchased Apps</a>.</p>",
        "content_text": "Source facts\nMicrosoft’s renewal procedure downloads a fresh Apple location token and updates the existing token in Intune. A location token is supported in only one Intune tenant and one device-management solution at a time. Deleting the token also removes its associated apps and assignments. The displayed expiration can take time to reflect a successful renewal. Microsoft Learn.\nApplicability\nUse this procedure boundary for routine token renewal, not an unplanned migration between management systems. Identify the Apple location and the corresponding existing Intune token before obtaining replacement token material.\nDSE recommendation\nMake the renewal record point to the existing token object and its app associations. Have the administrator confirm the location with a second reviewer before upload, and protect the downloaded token through the organization’s credential-handling process. Do not delete and recreate the object merely because the expiration display has not refreshed. Escalate a genuine location or tenant mismatch as a separate migration decision.\nVerification\nRefresh the token view until the updated expiration is observable, then synchronize and compare the associated app and assignment inventory with the pre-renewal record. Validate a representative managed app workflow after renewal. Keep the token contents out of screenshots and tickets; retain object identifiers, dates observed, and the actual synchronization outcome instead.\nOfficial references\nMicrosoft Learn: Manage Apple Volume-Purchased Apps.",
        "content_markdown": "## Source facts\n\nMicrosoft’s renewal procedure downloads a fresh Apple location token and updates the existing token in Intune. A location token is supported in only one Intune tenant and one device-management solution at a time. Deleting the token also removes its associated apps and assignments. The displayed expiration can take time to reflect a successful renewal. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/app-management/deployment/manage-vpp-apple).\n\n## Applicability\n\nUse this procedure boundary for routine token renewal, not an unplanned migration between management systems. Identify the Apple location and the corresponding existing Intune token before obtaining replacement token material.\n\n## DSE recommendation\n\nMake the renewal record point to the existing token object and its app associations. Have the administrator confirm the location with a second reviewer before upload, and protect the downloaded token through the organization’s credential-handling process. Do not delete and recreate the object merely because the expiration display has not refreshed. Escalate a genuine location or tenant mismatch as a separate migration decision.\n\n## Verification\n\nRefresh the token view until the updated expiration is observable, then synchronize and compare the associated app and assignment inventory with the pre-renewal record. Validate a representative managed app workflow after renewal. Keep the token contents out of screenshots and tickets; retain object identifiers, dates observed, and the actual synchronization outcome instead.\n\n## Official references\n\n[Microsoft Learn: Manage Apple Volume-Purchased Apps](https://learn.microsoft.com/en-us/intune/app-management/deployment/manage-vpp-apple)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-339-renew-an-apple-app-location-token-without-replacing-its-intune-record/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-339-renew-an-apple-app-location-token-without-replacing-its-intune-record/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-339-renew-an-apple-app-location-token-without-replacing-its-intune-record/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Renew an Apple app location token without replacing its Intune record",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-339-renew-an-apple-app-location-token-without-replacing-its-intune-record/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-339-renew-an-apple-app-location-token-without-replacing-its-intune-record/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-339-renew-an-apple-app-location-token-without-replacing-its-intune-record/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-339-renew-an-apple-app-location-token-without-replacing-its-intune-record/",
                "headline": "Renew an Apple app location token without replacing its Intune record",
                "description": "How should an expiring Apple location token be renewed without discarding associated app assignments?",
                "abstract": "How should an expiring Apple location token be renewed without discarding associated app assignments?",
                "articleBody": "Source facts\nMicrosoft’s renewal procedure downloads a fresh Apple location token and updates the existing token in Intune. A location token is supported in only one Intune tenant and one device-management solution at a time. Deleting the token also removes its associated apps and assignments. The displayed expiration can take time to reflect a successful renewal. Microsoft Learn.\nApplicability\nUse this procedure boundary for routine token renewal, not an unplanned migration between management systems. Identify the Apple location and the corresponding existing Intune token before obtaining replacement token material.\nDSE recommendation\nMake the renewal record point to the existing token object and its app associations. Have the administrator confirm the location with a second reviewer before upload, and protect the downloaded token through the organization’s credential-handling process. Do not delete and recreate the object merely because the expiration display has not refreshed. Escalate a genuine location or tenant mismatch as a separate migration decision.\nVerification\nRefresh the token view until the updated expiration is observable, then synchronize and compare the associated app and assignment inventory with the pre-renewal record. Validate a representative managed app workflow after renewal. Keep the token contents out of screenshots and tickets; retain object identifiers, dates observed, and the actual synchronization outcome instead.\nOfficial references\nMicrosoft Learn: Manage Apple Volume-Purchased Apps.",
                "datePublished": "2026-09-10T00:26:17+00:00",
                "dateModified": "2026-09-10T01:40:03+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-339-renew-an-apple-app-location-token-without-replacing-its-intune-record/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-339-renew-an-apple-app-location-token-without-replacing-its-intune-record/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Renew an Apple app location token without replacing its Intune record"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 215,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Manage Apple Volume-Purchased Apps - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/app-management/deployment/manage-vpp-apple"
                }
            }
        ]
    }
}