Create the Apple MDM Push certificate (required for all Apple management)
The MDM Push certificate is the master key that lets Intune manage ANY iPhone, iPad or Mac. Download a request from Intune, sign it at Apple's push portal, upload it back. Renew yearly with the SAME Apple ID or every device re-enrols.
- A Microsoft 365 / Office 365 tenant with a Microsoft Intune (Plan 1) licence assigned to your admin account — if you do not have Intune yet, there is no console to open (foundation guide coming).
- An Apple Business Manager account and the organisation Apple ID that owns it.
Apple Push Certificates Portal (identity.apple.com/pushcert) + Intune needs a human to sign in, so this stays manual on purpose. Decolla makes it painless: the wizard shows these exact screens at the moment you need them and flags precisely what to bring back — a token, a file, an ID — so the automated steps either side of it run without a hitch.
- Decide which organisation Apple ID will OWN this certificate, and write it down — the yearly renewal MUST use the exact same account, so never use a personal Apple ID or one tied to a single employee.
- Intune Administrator (or Global Administrator) access to sign in at intune.microsoft.com.
- A shared calendar or ticket system you actually check — the certificate expires 12 months from the day you create it, and its lapse breaks management for every Apple device at once.
- In Intune (intune.microsoft.com) go to Devices > Enrollment > Apple tab > Apple MDM…
- Tick 'I agree', then click 'Download your CSR' to save the .csr file locally.
- Go to https://identity.apple.com/pushcert and sign in with the organisation Apple…
- Click 'Create a Certificate', accept the terms, choose the .csr file, then click…
- On the confirmation screen click 'Download' to get the .pem certificate.
- Back in Intune, enter the same Apple ID, browse to the .pem, and click Upload.
- Confirm Status = Active with a 1-year expiry date shown.
Put these on a schedule
| Step | Recurring action to diarise |
|---|---|
| Step 3 | Record which Apple ID this is in your shared password vault now — the yearly renewal has to reuse it. |
| Step 7 | Diarise the expiry date NOW, and set the reminder for at least a week before. When it is due, RENEW the existing certificate (same Apple ID) — do not create a new one. |
If it goes wrong
The failures people actually hit on this process, each with the diagnosis and fix:
- Renew or recreate the Apple MDM push certificate in Intune? — Renew — never recreate — your Intune APNs certificate. Why device trust follows the push topic, what the Apple ID actually controls, and the safe path.
- APNs certificate expired in Intune: recovery options — What happens when your Intune APNs certificate expires, the documented 30-day renewal grace period, and when non-removable profiles force a full wipe.
- Apple tokens in Intune: APNs, ADE and VPP renewal explained — The APNs certificate, ADE enrolment token and VPP token all expire yearly and each breaks something different. A one-page matrix and the renewal rules.
See it on a real device.
Decolla is in private build — early-access members see a build defined, deployed and rolled back first.
Get early access