How do you get your app onto a company's managed devices?
When IT installs your app on company phones, the purchase decision becomes a deployment project. This page explains the three routes to managed devices, the steps on Apple and Android, and what your team has to prepare so the customer's IT admin can roll out the app without a support ticket.
How do company devices get a work app?
Most companies use a device management tool (MDM, or EMM on Android) to push apps to staff phones. For your app, there are three routes: the public store version installed through device management; an Apple custom app distributed privately to named organizations; or a private app published only to chosen organizations in Managed Google Play.
The public route is simplest and keeps one version of your app. The private routes are for builds that should not be listed publicly, such as a version with a customer's own branding or integrations.
Company app catalogue
Managed by Westvale Foods IT
Installing CheckFlow
Welcome, Dana
Signed in with your Westvale account.
Which distribution route should you use?
Choose the route by asking two questions: does this customer need a different build, and should the app be hidden from the public store? If the answer to both is no, use the public app.
| Route | When to use it | What you build | What the customer's IT does |
|---|---|---|---|
| Public app on managed devices | Almost every company customer | Company sign-in, support for managed settings where available | Adds the public app in its device management tool and pushes it |
| Apple custom app | A build only certain organizations may see, on iPhone or iPad | A separate custom app listing, set as private for named organizations | Gets it in Apple Business Manager, then installs by MDM or redemption codes |
| Private app in Managed Google Play | An Android build only certain organizations may see | A private app published to their organization | Finds it in its EMM console and pushes it |
| Direct installation outside the stores | Rare; internal enterprise tools | Separate signing and update process | Treat as a special project; not covered here |
Large customers also ask whether the app supports their identity provider and whether data stays inside work profiles. Those answers belong in the checklist on company purchasing.
How does Apple custom app distribution work?
Apple's custom apps are distributed privately to specific organizations through Apple Business Manager or Apple School Manager. The organization then installs them on devices through its device management tool or hands out redemption codes. The app still goes through App Review.
- Confirm the need. Check that the public app with company sign-in cannot meet the requirement.
- Get the customer's organization details. Their admin provides the identifier you need to make the app available to them.
- Set up the custom app in App Store Connect with private availability for the named organizations, and submit it for review with working reviewer access.
- Customer admin obtains the app in Apple Business Manager, then assigns it to devices by MDM or distributes redemption codes.
- Plan updates. Each update to the custom build is shipped and reviewed like any other version.
Apple announced Apple Business in March 2026, combining Business Manager, Business Essentials and Business Connect, with built-in device management and Managed Apple Accounts, available from April 14, 2026. Smaller customers who never used separate MDM software may now manage devices this way, so expect device questions from firms of 20 or 30 people, not only large ones.
How do private apps in Managed Google Play work?
On Android, companies use an EMM tool linked to Managed Google Play. Publishing a private app makes it available only to the organizations you choose, up to 1,000 of them, and it appears in their EMM console for IT to approve and push.
- Ask the customer for their organization ID from their Managed Google Play setup.
- In Play Console, restrict the app to the named organizations rather than publishing publicly.
- Pass review as usual, with test credentials if the app needs a login.
- Customer IT approves the app in the EMM console and assigns it to devices or work profiles.
- Ship updates through Play Console; managed devices receive them under the customer's update policy.
| Item | What to provide | Why IT needs it |
|---|---|---|
| Install guide | One page per platform with screenshots | So the admin does not have to guess |
| Sign-in settings | Supported identity providers and setup steps | Staff should not create personal passwords |
| Managed settings | Keys your app reads, such as server or site ID, if supported | Pre-configures the app for every device |
| Test account | A working login for the admin's test device | Lets IT verify before rollout |
| Support contact | Named person and response time | Questions arrive during rollout day |
Write the IT admin's runbook before the deal closes.
An admin who has a one-page install guide, sign-in settings and a test account deploys in hours. One who has to email support for each step deploys in weeks, and the users lose interest in the meantime.
What goes wrong with managed distribution?
- Custom builds by default. Each private build multiplies testing and release work. Many customers only needed company sign-in.
- Personal sign-up on managed phones. If the first screen asks for an email and password, IT will block the rollout.
- No offline check. Managed field devices often run on poor signal; test the first-run flow without a connection.
- Losing attribution. Apps pushed by IT do not come from your ads or listing, so tag company accounts separately in analytics.
- Forgetting the user. Even with IT installing the app, staff need a first useful task on day one. See onboarding.
- Trade-off: a private app hides customer-specific features from competitors, but it removes the store listing, reviews and organic discovery that bring in new individual users.
What should you track for managed deployments?
| Metric | Question it answers | Where to find it |
|---|---|---|
| Devices assigned vs users signed in | Did people actually open the app? | Customer admin report and your sign-in events |
| Days from contract to first sign-in | How fast does IT deploy? | CRM date and product analytics |
| First-week activation of managed users | Do pushed users reach first value? | Product analytics, filtered by company account |
| Support tickets during rollout | Which step confuses admins? | Help desk tags |
| Active seats at 90 days | Is the rollout sticking? | Billing and product analytics |
A rollout that installs on every device but stalls at first sign-in is an onboarding problem, not a distribution one. The pilot guide shows how to test this with one site first.
Frequently asked questions
Do companies need a private app to deploy my app?
Usually not. Most install the public store app through device management and staff sign in with company accounts.
What is an Apple custom app?
An app distributed privately to specific organizations through Apple Business Manager or Apple School Manager, installed by device management or redemption codes.
Does a custom app still go through App Review?
Yes. Custom apps are reviewed like other App Store apps, so provide working reviewer access.
How many organizations can receive a private app on Google Play?
Up to 1,000 organizations through Managed Google Play, where it appears in their EMM console.
What is the difference between MDM and EMM?
Both describe tools for managing company devices and apps. EMM is the term Google uses for Android tools connected to Managed Google Play.
What should I send a customer's IT admin?
An install guide, sign-in settings, any managed settings keys, a test account and a named support contact.
Does Apple Business replace MDM tools?
Apple Business includes built-in device management, which smaller companies may use. Larger companies often keep their existing tools.
Sources & further reading
Regulator rules, platform policies and local data change. These sources let you check the facts on this page, last checked October 6, 2026.