# Self Service Hub

> Let end users install approved Apple applications on their own devices from a catalog you define.

Source: https://docs.capaone.com/capaone/mobile-manager/apple-mdm/self-service-hub/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

The **Self Service Hub** (Management → Self Service Hub) lets end users install approved Apple
applications on their own devices without contacting IT. You define what is available — users
choose what they need from the catalog.

This reduces help desk ticket volume for routine software requests and gives users faster access
to tools they need, while IT retains full control over what can be installed.

## How it works

1. An IT administrator creates a Self Service item in CapaOne, linking it to an Apple application
   already configured in Mobile Manager.
2. The item becomes visible in the self-service catalog on the user's Apple device.
3. The user opens the catalog, finds the app, and clicks to install it — no IT involvement
   required.
4. CapaOne handles the installation using the same deployment mechanism as any other managed app.

## Creating a Self Service item

1. Go to **Management → Self Service Hub** and click **New**.
2. Give the item a name and optionally a description that helps users identify what it does.
3. Select the Apple application to make available.
4. Configure which groups or users can see the item in their catalog.
5. Save.

The item appears in the catalog for the specified users immediately.

## What can be offered

Apple VPP apps and other Apple applications already configured in Mobile Manager can be offered
through Self Service. The application must exist in CapaOne before it can be added to the Self
Service Hub.

## Prerequisites

### Azure integration

Self Service Hub requires **Microsoft Entra ID (Azure AD) integration** to be configured in
CapaOne before users can access the catalog. Users are identified by their synced directory
account — without the integration, the hub cannot authenticate who is accessing it.

Set up the integration under **Management → Integrations** before creating Self Service items.
See [Integrate CapaOne with Entra ID](/capaone/integrations/integrate-capaone-with-entra-id/).

### User login on device

When a user opens the Self Service Hub app on their Apple device, they are prompted to **sign in
with their company Microsoft credentials**. This is how CapaOne identifies the user and
determines which items they are authorized to see in the catalog.

Users must have a valid account in your Entra ID directory and be synced to CapaOne for login
to work.

## Good to know

- **Apple only** — Self Service Hub currently supports Apple devices (iOS, iPadOS, macOS). It is
  not available for Windows or Android devices.
- **IT controls the catalog** — only items you explicitly add appear in the user's self-service
  view. Users cannot browse or install anything outside of what you have approved.
- **Installation is managed** — when a user installs an app through Self Service, it deploys
  through CapaOne's standard app deployment pipeline. The installation is logged and the device
  shows the app as assigned.
- **Self Service requires the MDM profile** to be active on the device. If a device is not
  enrolled, it cannot access the Self Service catalog.
