Posted on 09-20-2023 01:23 PM
My users are having an issue where when they attempt to install an app through the self-service portal, they get an error stating that the associated apple ID is not allowed to make purchases.
It also states in the logs that No license was found for app which is false as there is more than enough licenses available.
I'm new to this so I'm not 100% sure if I'm missing something here.
Posted on 09-20-2023 02:46 PM
I have seen this happen a few times when the user who is logged in and initiating the Self Service install is not MDM capable. You will see the "MDM Capable Users" in the General section of the Mac's inventory record. If the user of the Mac is not listed there, they need to be converted to an MDM capable user. When I needed to do this, I used this command:
sudo jamf mdm -userLevelMdm
There are more details here: https://learn.jamf.com/bundle/jamf-pro-documentation-10.40.0/page/MDM-Enabled_Local_User_Accounts.ht...
In my case, the reason why my current logged in user was not MDM capable was because the person who setup the Mac insisted on setting up his "admin account" first, then enrolling the Mac in Jamf Pro using the enrollment URL. This was not an automated enrollment through PreStage and Apple Business Manager. After he setup the computer, he then manually created the account for the person who would be using the system. When I was troubleshooting why apps from VPP would not install, and instead launch the App Store and give the error you mentioned, Jamf told me to use the command I posted above after we saw that the user was not MDM capable. You didn't describe how you are enrolling and setting up your Macs, but if you are starting with an account that is not the one that the user of the system will be using, you should setup the Mac with the actual user's account first, and then have a policy create what ever admin account you want installed on the system. Of course using Apple Business Manager, and a PreStage will ensure that the user of the computer is always the first account that gets setup and you won't have this problem. Zero Touch Provisioning is the gold standard of Mac setup. Use it if you are able to.
Posted on 09-21-2023 05:36 AM
To clarify, these are all happening on iPads and iPhones. I did manually create the users in Apple Business Manager and JAMF Pro. Does the documentation apply to iOS devices too, or just Macs? Thanks!
Posted on 09-22-2023 05:22 AM
You should check that "Assign Content Purchased in Volume" turned on in Managed Distribution for each app. Did you purchase the apps in Apple Business Manager? Is there a VPP token installed in Jamf Pro?
Posted on 09-29-2023 06:38 AM
I am also seeing this issue on an iPad this morning. This app pushed out fine earlier this school year.