Purpose
Ensure continued management of Apple devices (iPhones, iPads, Macs) in Microsoft Intune by renewing the Apple MDM Push Certificate before expiry.
Quick Reference Summary
- Confirm which Apple ID was used for the existing MDM Push Certificate.
- This is critical as using a different Apple ID will break the link between Intune and enrolled devices.
- You can find this in Intune Admin Center → Devices → iOS/iPadOS → Enrollment → Apple MDM Push certificate.
- Check the expiration date of the current certificate to plan ahead (renew before expiry).
- Confirm current admin access:
- Microsoft Entra ID Global Admin rights
- Access to the Apple ID mailbox for verification
Tips & Recommendations
- Set a recurring calendar reminder 30 days before expiry.
- Store the Apple ID in IT Glue.
- Keep a shared email alias for Apple ID (e.g.,
applemdm@domain.com) to avoid staff dependency.
Vendor Resources
https://learn.microsoft.com/en-us/intune/intune-service/enrollment/apple-mdm-push-certificate-get
1) Log into Microsoft Intune
- Go to Microsoft Intune admin center:
https://intune.microsoft.com - Navigate to:
Devices → iOS/iPadOS → Enrollment → Apple MDM Push certificate- Confirm the Apple ID used for current deployment if applicable
2) Download the CSR
- Click Renew certificate.
- Download the .csr file provided by Intune, you’ll upload this to Apple next.
3) Log into the Apple Push Certificates Portal
- Visit: https://identity.apple.com/pushcert
- Sign in with the same Apple ID used for the original certificate (see step 1.2).
4) Locate and Renew the Certificate
- Find the existing certificate (check the Serial Number / Common Name, it should match Intune).
- Click Renew.
- Upload the .csr file you downloaded from Intune (see step 2.2).
- Once renewed, download the new certificate (.pem) from the portal.
5) Upload the New Certificate to Intune
- Back in the Intune admin center → Apple MDM Push certificate section
- Click Upload your new MDM push certificate
- Upload the .pem file you just downloaded (see step 4.3).
6) Validation & Testing
- Refresh the Intune page and confirm:
- New expiration date reflects 1 year from renewal.
- Status shows as Active.
- Test communication:
- Push a test policy or sync command to a managed iOS device.
- Confirm it completes successfully.
- Update internal documentation / password vault:
- Note the Apple ID used.
- Record the new expiration date.
- Save renewal steps link for next year, and schedule it so that it doesn't get missed.