AirWatch配置VPP托管分发时sToken已存在于对等组织组的问题求助
Let's break down what's causing this error and walk through how to fix it, since you're new to MDM setups:
Why this error pops up
Your sToken is directly tied to your Apple Business Manager (ABM) organization, and AirWatch enforces a key rule: the same sToken (or an aliased version of it) can't be added to multiple peer-level Organizational Groups (OGs). Peer OGs sit at the same level in your AirWatch hierarchy—they don't share resources by default, so duplicate sTokens here are blocked to avoid conflicts in app licensing and distribution.
Step-by-step solutions
1. Check for existing sTokens in peer OGs
First, verify if another OG at the same level as yours already has this sToken registered:
- Log into AirWatch with a top-level administrator account (if you don’t have this access, reach out to your AirWatch admin—you’ll need it to view cross-OG settings).
- Navigate to
Groups & Settings > All Settings > Devices & Users > Apple > VPP Managed Distribution. - Scan the list of registered sTokens to see if any entry links to your ABM organization ID (the one you used to generate the sToken).
- If you find a duplicate:
- Option 1: Remove the sToken from the peer OG (only do this if that OG no longer needs access to your ABM app pool).
- Option 2: Adjust your OG’s hierarchy—move your current OG to be a sub-group of the OG that already has the sToken. Sub-OGs inherit VPP settings from their parent, so you’ll gain access to the sToken without duplication.
- If you find a duplicate:
2. Generate a fresh sToken in ABM
Sometimes residual alias data from old sTokens can cause hidden conflicts. Try creating a brand new token:
- Go to your ABM dashboard, head to Settings > Apps and Books > VPP Tokens.
- Delete the old sToken (if it’s no longer in use) and generate a new one. Use a unique description for this token—avoid reusing names from old tokens.
- Download the new sToken file and try importing it into your AirWatch OG again.
3. Use the top-level OG for shared sTokens (best practice)
If you plan to use this ABM app pool across multiple OGs, the cleanest approach is:
- Add the sToken to your top-level AirWatch OG (the root group).
- Configure child OGs to inherit VPP settings from the top level. This way, all sub-groups can access the same app distribution pool without needing to add the sToken multiple times.
Quick tip for beginners
Avoid deleting sTokens unless you’re 100% sure they’re not being used—this can break app distribution for other teams or devices. If you’re still unsure, reach out to AirWatch support or your organization’s MDM admin to help verify the OG hierarchy and sToken usage.
内容的提问来源于stack exchange,提问作者Pelin Konaray

