Enterprise iOS App Distribution: The Complete Guide (2026)
Every way to get a private iOS app onto employee iPhones in 2026 — Custom Apps, TestFlight, Unlisted Apps, enterprise signing, MDM and MDM-free portals — with honest costs, failure modes, and a decision framework.
Who this guide is for
You have an iOS app that does not belong in the public App Store — an internal tool, a field-operations app, a client-facing app for a specific customer — and you need it on somewhere between ten and a few thousand iPhones and iPads. This guide covers every route Apple offers in 2026, what each one genuinely costs, where each one breaks, and how to choose.
It is written by the team behind AppDeploy, a private app distribution platform, and we link to our own product where relevant — but the guide covers every option including the ones we do not sell, because the fastest way to lose your trust is to pretend TestFlight and Custom Apps do not exist.
The six ways an iOS app can reach a device
Apple offers six distribution routes, and almost every enterprise headache comes from using one of them beyond what it was designed for. In brief: the public App Store (everyone can see it), TestFlight (beta testing, builds expire after 90 days), Custom Apps through Apple Business Manager (private distribution over App Store infrastructure), Unlisted App Distribution (App Store hosting, link-only visibility), the Apple Developer Enterprise Program (self-signed in-house distribution — now heavily restricted), and MDM-based managed app installation (silent install on enrolled devices).
Most organisations end up combining two or three. The rest of this guide takes each in turn, then gives you a decision framework.
TestFlight: excellent at the job it was built for, painful beyond it
TestFlight is Apple's beta-testing service: up to 10,000 external testers, builds delivered through the TestFlight app, light-touch beta review. For testing pre-release builds it is genuinely excellent, and it is free.
The problems start when teams use it as a permanent distribution channel. Every build expires 90 days after upload — so your 'production' app dies quarterly unless someone remembers to push a new build. Testers must install the TestFlight app first, invitations are managed by hand or via public links you cannot meaningfully audit, and there is no per-user entitlement, no install evidence, and nothing you can show an auditor. If you have ever heard 'the app stopped working again' from a field team on a Monday morning, this is usually why.
Use TestFlight for what it is: the testing stage before one of the real distribution routes below.
The Apple Developer Enterprise Program: the route that closed
For a decade, the Enterprise Program (ADEP) was the default answer: pay Apple $299 a year, sign apps with your own certificate, install them on any device with no App Store involvement. That era is over for most companies.
After high-profile misuse — including the January 2019 revocation of Facebook's and Google's enterprise certificates for distributing consumer research apps — Apple tightened eligibility hard. New applications face strict criteria (Apple's published guidance points to organisations of 100+ employees with a demonstrated need no other route can meet), long review queues, and frequent refusal. Existing members keep renewing, but a revoked or lapsed certificate kills every installed app at once: the apps simply stop launching.
If you already hold ADEP membership, enterprise-signed .ipa delivery remains legitimate and useful — several platforms, including AppDeploy, will host and deliver your signed builds with proper access control and audit trails. If you do not already hold it, plan on one of the other routes; a distribution strategy that depends on being granted ADEP in 2026 is a plan to be disappointed.
Custom Apps through Apple Business Manager: Apple's intended answer
Custom Apps are how Apple wants private business distribution done in 2026. Your app goes through App Review once, but instead of appearing publicly it is offered privately to the specific organisations you choose, through Apple Business Manager (ABM). Distribution then works through Apps & Books: licence-based assignment (formerly called VPP) to devices or Managed Apple IDs, or redemption codes handed to individual users.
The strengths are real: no 90-day expiry, App Store-grade hosting and updates, no certificate for you to manage, and BYOD-friendly installation. The frictions are also real: your app must pass App Review (a problem for very rough internal tools), the recipient organisation needs ABM set up, and the raw ABM workflow — token management, licence assignment, invitation emails for Managed Apple IDs — is where most rollouts stall. This is the layer distribution platforms exist to smooth: AppDeploy, for example, syncs Apps & Books content, automates the Managed Apple ID invitation flow, and gives employees a branded portal instead of raw mechanics.
A related option, Unlisted App Distribution, is worth knowing: Apple hosts your app on the public App Store but it is reachable only by direct link — no search, no charts. You request it from Apple with a justification. It suits apps for a broad but defined audience, such as a contractor workforce, where ABM setup on the receiving side is impractical.
MDM-managed installation: silent, powerful, and priced accordingly
Mobile Device Management can install apps silently on enrolled devices — no tap, no App Store visit, combined with configuration profiles, OS update enforcement and device actions. On company-owned, supervised hardware it is the gold standard for zero-touch operation, and paired with Automated Device Enrollment (ADE) a new iPhone configures itself out of the box.
Two costs come with it. The first is money: mainstream MDM is priced per device per month — roughly $2.50–$8 depending on vendor — which for 100 devices is anywhere from about £2,200 to £9,800 a year, mostly buying device-management capability you may not need. The second is consent: enrolment on personal (BYOD) devices means asking employees to accept management of their own phone, which in practice suppresses adoption and raises legitimate privacy questions your HR and legal teams must answer. Apple's User Enrollment mode limits what employers can see, but the conversation still has to happen.
The honest question is whether app delivery is the job, or device management is. If you need OS policy enforcement, remote wipe and conditional access, you need MDM — see our comparisons against Jamf Pro, SimpleMDM and Applivery for how the options differ. If you need your app on phones, MDM-for-everyone is usually the expensive way to get it.
The MDM-free portal model
The newest pattern separates distribution from management. Employees open a branded web portal, sign in, and install the apps they are entitled to — via Custom App licence assignment, redemption codes, or enterprise-signed delivery where ADEP membership exists. No device enrolment, no management payload on personal phones, and every install recorded against a person rather than guessed at.
For the organisations this guide is aimed at — 30 to 300 people, one to a handful of private apps, mixed company and personal devices — this model usually covers 80% of devices, with MDM-based silent install reserved for the company-owned subset that genuinely needs zero-touch. That hybrid is exactly how AppDeploy is structured: a flat-price portal for everyone (£599/year), with per-device AutoDeploy capacity added only for the devices that need silent installation.
The trade-off to state plainly: a portal cannot force anything onto a device. If a device must receive an app without its user's cooperation, that device needs enrolment — no vendor honestly claims otherwise.
What the options cost at 100 devices
Taking public list pricing checked in August 2026, distributing one private app to 100 people looks roughly like this. TestFlight: free, plus the quarterly expiry tax on your team's time and credibility. ADEP self-hosting: $299/year plus your own hosting, signing and access control — if you can get in. Jamf Pro-class MDM: about £9,800/year. Lightweight MDM such as SimpleMDM: about $3,000/year, with every device enrolled. Applivery's app-distribution tiers: €990–€5,990/year depending on user counts and custom-domain needs. An MDM-free portal such as AppDeploy: £599/year flat, rising to roughly £2,300/year only if all 100 devices also need silent MDM install.
The pattern to notice: per-device pricing punishes exactly the thing you are trying to do — reach more people. Flat or capacity-based pricing keeps the marginal cost of the 101st employee at zero.
Security and compliance: what reviewers actually ask
Whichever route you choose, procurement and security reviews converge on the same questions. Who can install this app, and how is that entitlement removed when someone leaves? Where is the evidence of who installed what, and when? Are binaries hosted and transferred securely, with integrity guarantees? What happens when a signing certificate or push certificate expires? Can you export the audit trail?
Two certificate deadlines deserve calendar entries wherever you land: enterprise provisioning profiles (annual) and the Apple MDM push certificate (annual — if it lapses, silent delivery stops for every device simultaneously). And if your organisation pursues Cyber Essentials or ISO 27001, note that the application-update requirement expects you to evidence that deployed app versions are current — which is dramatically easier when your distribution tool records it as a by-product. This is why audit trails and compliance evidence are not enterprise garnish on a distribution platform; they are the part you will be asked for.
A decision framework
Distributing to under 25 known testers, pre-release: TestFlight, no argument. Production app, recipients are other organisations with ABM: Custom Apps. Production app, broad defined audience without ABM: Unlisted App Distribution. Fleet is entirely company-owned, supervised, and you also need policy enforcement: full MDM, with app delivery riding on it. You hold ADEP already and need App Review-free delivery: enterprise-signed hosting with proper access control. Mixed fleet, one to a few private apps, and the goal is adoption with audit evidence: portal-first distribution, with MDM capacity only for the devices that need silent install.
If two answers seem to apply, choose the lighter one and upgrade the specific devices that prove the need. Distribution mistakes in the heavy direction are expensive and sticky; mistakes in the light direction cost a per-device add-on.
A first-two-weeks rollout plan
Day one: pick the route with the framework above; set up Apple Business Manager if you do not have it (free, and worth doing regardless of route). Days two to three: get your app into the chosen channel — App Review submission for Custom Apps, or signed build upload for portal or MDM delivery — and configure your distribution surface: branding, entitlements, who may install what.
Week one: pilot with five to ten friendly users on their real devices; fix the install-guidance gaps they find — they will find some. Week two: announce to everyone with a single link or QR code, watch install telemetry rather than assuming, and chase the silent non-adopters personally — non-adoption is nearly always awareness, not refusal. End of week two: check your evidence — can you say who has the app, which version, on which device? If yes, you have a distribution system. If no, you have a link people once clicked.
Common failure modes to pre-empt: a push certificate or ADE token uploaded by a developer using a temporary tunnel URL that later dies (use a stable HTTPS hostname from day one); Apple Business Manager devices left unassigned to your MDM server so enrolment times out during Setup Assistant; and redemption-code pools quietly running to zero. All three produce the same symptom — 'it just spins' — hours or days after the actual mistake.
Managed Apple IDs, federation, and why invitations stall
Licence-based Custom App assignment to users requires the recipient to hold a Managed Apple ID — an Apple account owned by the organisation rather than the individual. ABM can federate these with Microsoft Entra ID or Google Workspace, so employees sign in with their normal work identity, or create them directly.
The stall point in real rollouts is the invitation: Apple issues a one-time invite URL that must reach the right person while it is valid, and raw ABM leaves that step to you. If your rollout dies at 'I got a weird Apple email and ignored it', this is where. Automating the invite delivery and resend flow — with a record of who accepted — is one of the highest-value things a distribution platform does, and it is invisible until it is missing.
Device-based licence assignment sidesteps Managed Apple IDs entirely — the licence attaches to the device serial rather than a person — but it requires the device to be enrolled in MDM, which reopens the enrolment question on BYOD hardware.
What about Android?
Most fleets are not iOS-only. Android's equivalent landscape is simpler in one way — a signed APK can be installed without any Apple-style gatekeeping — and messier in another: 'sideloading' without management raises real security review questions, and Google's managed alternative (Managed Google Play with private apps) requires Android Enterprise enrolment much as Apple's managed routes require MDM.
The same portal-versus-management logic applies. If you need Android policy enforcement, use Android Enterprise through a UEM. If you need a private APK delivered to known people with an audit trail, portal delivery of a signed APK does the job — AppDeploy supports this on the Enterprise tier. Plan the two platforms together rather than letting each team pick its own route: reviewers ask about both, and one audit story is easier to tell than two.
Frequently asked questions
Can employees install a private app without any Apple ID at all? On a supervised, MDM-enrolled device, yes — device-based assignment and silent install need no Apple ID. On an unmanaged personal device, an App Store-mediated install (Custom Apps, Unlisted) uses the person's own Apple ID or a Managed Apple ID; an enterprise-signed install needs neither but requires ADEP membership on your side.
Does a private app need App Review? Only on App Store infrastructure: Custom Apps and Unlisted apps are reviewed; TestFlight builds get a lighter beta review; enterprise-signed and MDM-pushed in-house builds are not reviewed by Apple at all — which is exactly why Apple restricts who may sign them.
What happens when someone leaves? This is the question to ask any vendor. On managed devices, unassignment removes a managed app. Portal entitlements should be revocable per person, ideally driven automatically by your identity provider through SCIM. If the honest answer is 'the IPA is on their phone and we hope for the best', your distribution route has failed the leaver test.
Is 90 days really the TestFlight limit? Yes — each build expires 90 days after upload, testers get warnings, then the app stops launching. There is no paid tier that extends it. If that deadline is shaping your release calendar, you have outgrown TestFlight.