Self Service Hub
The Self Service Hub (Management → Self Service Hub) lets end users install approved Apple applications on their own devices without contacting IT. You define what is available — users choose what they need from the catalog.
This reduces help desk ticket volume for routine software requests and gives users faster access to tools they need, while IT retains full control over what can be installed.
How it works
Section titled “How it works”- An IT administrator creates a Self Service item in CapaOne, linking it to an Apple application already configured in Mobile Manager.
- The item becomes visible in the self-service catalog on the user’s Apple device.
- The user opens the catalog, finds the app, and clicks to install it — no IT involvement required.
- CapaOne handles the installation using the same deployment mechanism as any other managed app.
Creating a Self Service item
Section titled “Creating a Self Service item”- Go to Management → Self Service Hub and click New.
- Give the item a name and optionally a description that helps users identify what it does.
- Select the Apple application to make available.
- Configure which groups or users can see the item in their catalog.
- Save.
The item appears in the catalog for the specified users immediately.
What can be offered
Section titled “What can be offered”Apple VPP apps and other Apple applications already configured in Mobile Manager can be offered through Self Service. The application must exist in CapaOne before it can be added to the Self Service Hub.
Prerequisites
Section titled “Prerequisites”Azure integration
Section titled “Azure integration”Self Service Hub requires Microsoft Entra ID (Azure AD) integration to be configured in CapaOne before users can access the catalog. Users are identified by their synced directory account — without the integration, the hub cannot authenticate who is accessing it.
Set up the integration under Management → Integrations before creating Self Service items. See Integrate CapaOne with Entra ID.
User login on device
Section titled “User login on device”When a user opens the Self Service Hub app on their Apple device, they are prompted to sign in with their company Microsoft credentials. This is how CapaOne identifies the user and determines which items they are authorized to see in the catalog.
Users must have a valid account in your Entra ID directory and be synced to CapaOne for login to work.
Good to know
Section titled “Good to know”- Apple only — Self Service Hub currently supports Apple devices (iOS, iPadOS, macOS). It is not available for Windows or Android devices.
- IT controls the catalog — only items you explicitly add appear in the user’s self-service view. Users cannot browse or install anything outside of what you have approved.
- Installation is managed — when a user installs an app through Self Service, it deploys through CapaOne’s standard app deployment pipeline. The installation is logged and the device shows the app as assigned.
- Self Service requires the MDM profile to be active on the device. If a device is not enrolled, it cannot access the Self Service catalog.