HomeSetup guides › Create the Apple MDM Push certificate (required for all Apple management)
Setup guide · from scratch

Create the Apple MDM Push certificate (required for all Apple management)

The MDM Push certificate is the master key that lets Intune manage ANY iPhone, iPad or Mac. Download a request from Intune, sign it at Apple's push portal, upload it back. Renew yearly with the SAME Apple ID or every device re-enrols.

one-time human step · Apple Push Certificates Portal (identity.apple.com/pushcert) + Intuneassisted guide — Decolla walks you through this
≈ 20 min
Apple — iPhone, iPad & Mac · step 2 of 12 · ≈ 20 min‹ PreviousNext ›
Do these first — this guide assumes you already have:
The Decolla way — the one bit no tool can click for you.

Apple Push Certificates Portal (identity.apple.com/pushcert) + Intune needs a human to sign in, so this stays manual on purpose. Decolla makes it painless: the wizard shows these exact screens at the moment you need them and flags precisely what to bring back — a token, a file, an ID — so the automated steps either side of it run without a hitch.

⏱ A genuine human step — Decolla cuts the coordination around it, not the sign-in itself.
Before you start
  • Decide which organisation Apple ID will OWN this certificate, and write it down — the yearly renewal MUST use the exact same account, so never use a personal Apple ID or one tied to a single employee.
  • Intune Administrator (or Global Administrator) access to sign in at intune.microsoft.com.
  • A shared calendar or ticket system you actually check — the certificate expires 12 months from the day you create it, and its lapse breaks management for every Apple device at once.
0 of 7 done
Step 1. In Intune (intune.microsoft.com) go to Devices > Enrollment > Apple tab > Apple MDM Push Certificate.
Screenshot: Apple MDM Push Certificate pane in Intune (captured during a live customer build — coming to this page)
Why: This pane generates the request Apple must sign — every Apple-side action in this guide starts here, so it is the anchor screen.
Watch for: It lives under Devices > Enrollment > Apple, NOT under Tenant administration > Connectors and tokens — that wrong turn wastes the most time.
Step 2. Tick 'I agree', then click 'Download your CSR' to save the .csr file locally.
Screenshot: 'Download your CSR' link (captured during a live customer build — coming to this page)
Why: The CSR (certificate signing request) is your tenant's half of the trust — Apple signs it to prove the certificate genuinely belongs to your Intune tenant.
Watch for: The download link stays greyed out until 'I agree' is ticked — people miss the tick and think the button is broken.
Step 3. Go to https://identity.apple.com/pushcert and sign in with the organisation Apple ID.
Screenshot: Apple push portal sign-in (redact the ID) (captured during a live customer build — coming to this page)
Why: This portal is where Apple signs your CSR into a certificate Intune can actually use.
Don’t: Do NOT sign in with a personal Apple ID, or one tied to a single employee. This exact account is required every year to renew — if it walks out of the door, so does your ability to manage the fleet.
On a schedule: Record which Apple ID this is in your shared password vault now — the yearly renewal has to reuse it.
Step 4. Click 'Create a Certificate', accept the terms, choose the .csr file, then click Upload.
Screenshot: 'Create a Certificate' CSR upload screen (captured during a live customer build — coming to this page)
Why: Uploading your CSR here is the step that actually mints the signed push certificate.
Watch for: Choose the .csr you just downloaded from Intune — an old CSR from a previous attempt produces a certificate Intune will reject on upload.
Step 5. On the confirmation screen click 'Download' to get the .pem certificate.
Screenshot: Certificate download confirmation (captured during a live customer build — coming to this page)
Why: The .pem is the signed certificate itself — the thing Intune needs handed back to it.
Watch for: Download it now and keep it. Apple does not re-offer the same file later; if you lose it you have to create a fresh certificate, and creating a fresh one (rather than renewing) forces every device to re-enrol.
Step 6. Back in Intune, enter the same Apple ID, browse to the .pem, and click Upload.
Screenshot: Intune push cert upload with Apple ID field (captured during a live customer build — coming to this page)
Why: This closes the loop — Intune stores the signed certificate and binds it to the Apple ID that owns it.
Watch for: The Apple ID you type here MUST exactly match the one you signed in with at Apple's portal, or the upload fails validation with an unhelpful error.
Step 7. Confirm Status = Active with a 1-year expiry date shown.
Screenshot: Push cert pane showing Status Active + expiry (captured during a live customer build — coming to this page)
Why: Status: Active with a one-year expiry is the proof that Apple management is live for the whole tenant.
Don’t: Never let it lapse, and never 'renew' by creating a brand-new certificate or using a different Apple ID — either forces every Apple device to unenrol and be wiped to come back.
On a schedule: Diarise the expiry date NOW, and set the reminder for at least a week before. When it is due, RENEW the existing certificate (same Apple ID) — do not create a new one.

Put these on a schedule

StepRecurring action to diarise
Step 3Record which Apple ID this is in your shared password vault now — the yearly renewal has to reuse it.
Step 7Diarise the expiry date NOW, and set the reminder for at least a week before. When it is due, RENEW the existing certificate (same Apple ID) — do not create a new one.

If it goes wrong

The failures people actually hit on this process, each with the diagnosis and fix:

See it on a real device.

Decolla is in private build — early-access members see a build defined, deployed and rolled back first.

Get early access