Co-authored by @Nishitha Darbe
Introduction
In Apple device management using MaaS360, one of the most important design decisions is whether a device uses No Apple ID, a Personal Apple ID, or a Managed Apple ID. This choice directly affects how apps are installed, how much control IT admin has, and how much flexibility the end user gets.
Each scenario behaves differently when it comes to VPP apps, enterprise apps, App Store access, and in-app purchases. Understanding these differences is essential for designing the right deployment strategy for corporate-owned devices, BYOD environments, or fully managed setups.
In this blog, we will break down all three scenarios in a simple way and explain how app management works in each case.
No Apple ID Scenario in MaaS360: How App Management Works
When a device is enrolled in MaaS360 without any Apple ID, it works in a fully controlled, device-based setup. This is common for corporate-owned or shared devices, where everything is managed by admin and not linked to a specific user.
Since there is no Apple ID, the device is not connected to Apple services like the App Store or iCloud. Because of this, all apps must be pushed directly by MaaS360, and users cannot install anything on their own.
VPP App Installation
In this setup, device-based VPP apps work perfectly. Apps are assigned directly to the device and install silently, without asking for any Apple ID. The user doesn’t have to do anything.
On the other hand, user-based VPP apps do not work. These require an Apple ID to assign the license, hence there will be a prompt to login to apple account. If we do not login then the apps will fail to install.
Below images show VPP Device based- prompt to Install the app, and VPP user based app- prompt to login to apple account to install the app.


Enterprise Apps
Enterprise apps work without any issues. Since they are uploaded and distributed directly through MaaS360, they do not depend on Apple ID at all. IT admin can install, update, or remove them anytime.

App Store Usage
The App Store is basically not usable in this scenario. Without an Apple ID, users cannot download apps.

In-App Purchases
In this setup, in-app purchases are not possible because there is no Apple ID signed in.
- Users cannot buy apps, subscriptions, or upgrades
- No payment method is available on the device
- Everything is restricted to admin-approved apps only
Type of enrolment and its impact on app distribution/installation
In a No Apple ID setup, enrolment mainly enables a fully device-controlled model.
- With ADE/DEP (via Apple Business Manager) or Apple Configurator (supervised) where we need to Assign User after enrolment:
→ Device-based VPP apps install silently
→ User-assigned VPP apps are not supported.
→ App Store is not available
→ Enterprise apps work normally
- With Manual or Shared Enrolment
→ Same behaviour as above.
In short: Only device-based VPP + enterprise apps work. Fully controlled, no user flexibility.
Simple Examples-
- Shared office iPad: Admin installs the needed apps, and users just use them—no Apple ID, no extra apps.
- Store billing device: Only the billing app is available. Nothing else can be installed.
- Lobby kiosk: Runs one app only. Users can’t download or change anything.
Apple ID Scenario in MaaS360: Flexible App Usage with User Access
When a device has an Apple ID signed in (usually a personal Apple ID), it behaves more like a regular user device with added MDM control. This setup is common in BYOD, where users have some flexibility.
VPP App Installation
In this case, both device-based and user-based VPP apps work.
- Device-based VPP apps install silently via MaaS360.
- User-based VPP apps are assigned to the Apple ID and prompts the user to install.
This gives flexibility in how apps are distributed.


Enterprise Apps
Enterprise apps also work normally. Admin can push and manage these apps directly through MaaS360 without depending on the Apple ID.
App Store Usage
Since an Apple ID is present, users can access the App Store and install apps on their own.
This means:
- Users can download additional apps
- Not all apps on the device are controlled by admin


In-App Purchases
In this scenario, in-app purchases are allowed, because the device is tied to a personal Apple ID.
- Users can buy apps, subscriptions, or upgrades.
- Charges are billed for the Apple ID payment method.
- Admin generally has no control over these purchases.
Type of enrolment and its impact on app distribution/installation
In a Personal Apple ID setup, enrolment defines how much control admin has, while users still get flexibility.
- With ADE/DEP (via Apple Business Manager)and Manual Enrolment
→ Device-based VPP apps installation works fine
→ User-assigned VPP apps are supported. (linked to Apple ID)
→ App Store is fully accessible
→ Enterprise apps installation works
- With Account-Driven (User Enrolment)
→ Only user-based VPP is supported
→ App Store access with work/personal separation
→ Enterprise apps install in managed space
In short: Mix of admin-managed apps + user flexibility.
What This Means
This setup offers a balance between control and flexibility. Admin can push required apps, but users still have the flexibility to install their own apps.
In simple terms: Admin manages the important apps, but users can still add their own.
Simple Examples-
- Personal work phone: Company apps are installed, but the user can also download any other app.
- BYOD device: Work apps are managed by admin, while personal apps are installed by the user.
- Employee tablet: Required apps are pre-installed, but users can still browse and install from the App Store.
Managed Apple ID in MaaS360: Secure, Admin-Controlled App Usage
When a device uses a Managed Apple ID (from Apple Business Manager), it is part of a fully controlled enterprise setup. This is common in corporate environments where admin needs strong control over apps and data while keeping work usage separate from personal use.
Unlike a personal Apple ID, this setup does not allow full App Store flexibility. The device is mainly used for work-related apps managed by admin through MaaS360.
VPP App Installation
In this case:
- Device-based VPP apps → Yes
Apps are assigned to the device and install silently through MaaS360 without user action.
- User-based VPP apps → Yes
Apps are assigned to the user's Managed Apple ID through Apple Business Manager.
Enterprise Apps
Enterprise apps work normally in this scenario. Admin can push apps directly through MaaS360, and they can be installed, updated, or removed anytime without user involvement. Since they are distributed through MDM, they do not depend on the App Store or any Apple ID, making them fully controlled by admin.
App Store Usage
App Store access is restricted in this scenario.
This means:
- Users cannot freely browse or download apps.
- Only admin-approved apps are available through MDM.

In-App Purchases
In-app purchases are restricted.
- Managed Apple IDs are not meant for personal payments.
- Users cannot buy apps, subscriptions, or upgrades.
- Everything is controlled by organisation policies.
Type of enrolment and its impact on app distribution/installation
In a Managed Apple ID setup, enrolment supports a secure, enterprise-only model.
- With ADE/DEP (via Apple Business Manager)
→ Device-based VPP works best
→ User-based VPP is also supported
→ App Store is restricted
→ Enterprise apps work
- With Manual / Shared / Configurator
→ Same overall behaviour
In short: Only admin-controlled apps are allowed. No purchases, no App Store flexibility.
What This Means
This setup provides a secure and highly controlled environment. IT admin has full control over what gets installed, and users only get access to approved work apps.
In simple terms: the device only runs work apps provided by admin—nothing extra can be added by the user.
Simple Examples
- Corporate iPad: Only apps like email, Teams, and HR tools are available.
- Company-issued device: Preloaded with required apps, no App Store access.
- Field service tablet: Runs only job-related apps managed by admin.
Conclusion
To sum it up, the way MaaS360 manages apps on Apple devices depends not just on the Apple ID setup, but also on the type of enrolment used. Enrollment methods like Automated Device Enrolment (ADE/DEP) through Apple Business Manager, manual enrolment, or user enrolment define how much control admin has over the device, while the Apple ID determines how apps are owned and used.
A No Apple ID setup, especially when combined with DEP or supervised enrolment, gives full control to admin with complete restrictions on user activity, allowing only device-based VPP and enterprise apps. A Managed Apple ID, typically used with DEP, keeps the environment secure and work-focused, where all apps are centrally controlled and user actions like App Store access or purchases are restricted. In contrast, a personal Apple ID, often seen with manual or account-driven enrolment, offers the most flexibility—users can install apps, access the App Store, and make purchases, while admin continues to manage required work apps.
In simple terms, enrolment controls the device, Apple ID controls the user experience, and together they define the overall app management strategy in MaaS360.