The symptom

One BYOD iPhone could not obtain an application through Microsoft Company Portal.

Intune showed the following progression:

User requested application
VPP App licensing in progress
App installation failed
0x87D13B91

Support could not make Company Portal complete the VPP licensing path for that phone.

What made it weird

The failure was not universal.

Another iPhone installed the same application successfully. Intune also had a valid Apple VPP token alongside an expired token, so the visible expired token was not enough to explain the failure.

The strongest comparison came from the affected phone itself: the desired application installed successfully through the personal Apple App Store.

That meant the phone was not simply unable to install the application. The unresolved failure was specific to the managed Company Portal and VPP licensing path.

The evidence

Observation What it establishes
The affected phone reached VPP App licensing in progress and then failed with 0x87D13B91 The managed deployment failed during the observed licensing or installation sequence
Another iPhone installed the same application The failure did not affect every tested phone
A valid VPP token existed in parallel with an expired token The expired token alone did not demonstrate a complete VPP outage
The affected phone installed the app from the personal App Store The phone and application could complete a different installation path
Support could not restore Company Portal licensing on that phone The managed deployment remained unresolved

These observations narrow the failing path. They do not identify the failing component.

Diagnostic path

For a managed iPhone application that remains in a VPP licensing state:

  1. Record the exact status sequence. Preserve the displayed states and error code instead of reducing the incident to “the app would not install.”
  2. Compare affected and successful devices. Determine whether the failure is universal or limited to one device or assignment path.
  3. Compare the managed configuration. Check whether the devices use the same application assignment, licensing mode, Apps and Books location, token, enrollment state, and prior license state.
  4. Map token evidence to the affected deployment. A visible expired token is not causal evidence unless it can be connected to the application and assignment that failed.
  5. Test a separate delivery path when appropriate. A successful personal App Store installation can show that the device is capable of installing the application, while leaving the managed failure unresolved.
  6. Separate workaround from remediation. Restoring access to the app does not prove that Company Portal or VPP licensing was repaired.

The workaround

The application was installed on the affected phone through the personal Apple App Store. This solved the user’s immediate need.

It did not make Company Portal assign the VPP license, and the surviving evidence does not show that the managed deployment later recovered. It is also unknown whether the personal installation satisfied every intended management or compliance requirement.

The root cause

The root cause was not established.

Possible differences in assignment, licensing mode, Apps and Books location, token path, enrollment state, synchronization, or prior license state remained diagnostic leads. None was confirmed.

The expired token was background evidence, not a proven cause. A valid token existed in parallel, another iPhone installed the same application, and the affected phone succeeded through the personal App Store.

The lesson

A successful workaround can isolate the failing path without identifying the failing component.

The personal installation showed that the phone could install the application through another route. That shifted the troubleshooting boundary toward managed distribution and VPP licensing, but it did not explain why that path failed for this device.

Report both outcomes accurately:

  • the user obtained the application
  • the managed deployment remained unresolved

Those are not the same result.


FUCKUP.fail

When infrastructure makes no sense, follow the evidence.