Deploy with Microsoft Intune

Install the iPad app with device licensing and lock a device into it.

Before you start

Before you start, get free licenses in Apple School Manager or Apple Business Manager. It takes two minutes and is the same for every MDM: see Get free licenses.

  • iPads enrolled in Intune, running iPadOS 17.0 or later. Supervision (enrollment through Apple School Manager) is needed only for locking a device into the app.
  • An Apple location token in Intune under Tenant administration → Connectors and tokens → Apple VPP tokens. When you create it, set Automatic app updates to Yes.

Good to know: Menu names below follow the vendor's documentation as of September 2026. Consoles are redesigned often, so a label may differ slightly in yours. The order of the steps does not change.

Install the app

  1. After claiming licenses, open Apple VPP tokens, select your token and click Sync. Intune otherwise syncs once a day.
  2. Go to Apps → All apps and open Model Communicator. If you have several tokens, the VPP token name column shows which copy is which.
  3. Click Properties, then Edit next to Assignments.
  4. Under Required, click Add group and choose a device group that contains the iPads.
  5. Check that the assignment's License type is Device licensing. It is the default for new assignments, and it means no Apple Account is needed on the iPad.
  6. Click Review + save, then Save. Supervised iPads install silently at the next check-in.

Good to know: Assign as Required. Intune does not support the Available intent for device groups, and a student should not have to find the Company Portal to get a voice.

Lock an iPad into the app

An AAC device should stay in the AAC app. On a supervised iPad, Single App Mode does that from the MDM, with nothing for staff to remember. The alternatives are compared in the overview. In Intune:

  1. Go to Devices → Configuration → Create → New policy. Choose platform iOS/iPadOS and profile type Templates → Device restrictions.
  2. Open the Kiosk section. Set App to run in kiosk mode to Managed app and choose Model Communicator, or choose Store app and enter com.modelcommunicator.app.
  3. Assign the profile to a group that holds only the dedicated devices, and create it.

Heads up: Apps cannot update while an iPad is in kiosk mode. Move the device out of the kiosk group for a day during a break, let it update, and move it back.

Check that it worked

  • Under the app's Device install status, the iPads report Installed.
  • On the iPad, the app opens straight to the board, with no sign-in and no download.
  • With the kiosk profile assigned, the Home gesture stops working and the iPad returns to the app after a restart.