Intune and the APNs certificate: FAQ and common issues (2024)

First published on TechNet on Jun 11, 2018

Updated: 8/20/21- Post refresh.

By J.C. Hornbeck - Sr Support Escalation Engineer | Microsoft Endpoint Manager – Intune

Here in the Intune support organization, we often get questions relating to the Apple MDM push certificate – also known as the Apple Push Notification service (APNs) certificate - and how it plays a role in managing iOS devices. You can find general instructions in Get an Apple MDM Push certificate for Intune, but we want to address other questions and issues that you might have. We reviewed support cases with a few of our Intune support engineers, and collected common questions about APNs certificates and Intune that should help both new and experienced Intune administrators.

Why do I need to configure an APNs certificate in Intune?

Intune uses the Apple Push Notification service to communicate securely to your enrolled iOS devices, and Apple requires that each MDM service utilize their own certificate to establish a secure mechanism for devices to use when communicating on Apple’s push notification messaging network. Without the APNs certificate, devices could not be enrolled or managed by Intune.

How long is the APNs certificate valid?

By default, the APNs certificate is good for one year. This lifespan is determined by Apple. You must be sure to renew your APNs certificate before it expires.

What happens if I don’t renew my APNs certificate before it expires?

If your APNs certificate expires, enrollment of new iOS devices will fail, and you will experience problems managing existing iOS devices until a new APNs certificate is obtained.

IMPORTANTIf you renew anexpiredAPNs certificate outside of the grace period (30 days as of this writing), Apple will issue you a brand new certificate. When this happens, because the certificate is now different, you will be forced to unenroll and re-enroll all existing, Intune-managed iOS devices. Steps to unenroll (remove) an iOS device can be foundhere.

Do I need to renew my APNs certificate,or can I just get a new one?

It is critical that you renew your APNs certificate, not request a new one. This means you must ensure that you use the same Apple ID and renew the same certificate from Apple’s site. If you request a new certificate instead of renewing your existing certificate, you will be forced to unenroll and re-enroll all of your existing iOS devices. Steps to unenroll (remove) an iOS device can be foundhere.

How do I know if my APNs certificate is about to expire?
Apple should send an email notification to the Apple ID that requested the certificate at 30 days, 10 days, and 1 day prior to the expiration date. You can also see certificate expiration dates in theMicrosoft Endpoint Manager admin center. Go toDevice Enrollment>Apple Enrollment>Apple MDM Push certificate,and under Expiration you will see the date and time.

Intune and the APNs certificate: FAQ and common issues (1)

How do I renew my APNs certificate?

For instructions, see Get an Apple MDM push certificate.

If I have multiple APNS certificates, how can I tell which certificate I need to renew in theApple Push Certificates Portal?
On an enrolled iOS device, go toSettings>General>Device Management>Management Profile>More Details>Management Profile. UnderTopicyou will see a unique GUID that you can match up to the correct certificate in theApple Push Certificates Portal. Here is an example from a test device:

Intune and the APNs certificate: FAQ and common issues (2)

How can I change the Apple ID used for my existing APNs certificate?

Once a certificate has been requested using an Apple ID, you cannot use a different Apple ID to renew that same cert. However, Apple may be able to associate a new Apple ID with your existing certificate, which can then be used to renew it.Contact Apple support for more information.

Here are a couple common problems and solutions we have seen:

Problem
When attempting to upload the request file as part of certificate renewal, nothing happens when clicking the Upload button.

Solution
First try using another browser when renewing the certificate. If that does not resolve the problem, remove the Intune license from the user account being used to renew the certificate, then reassign the license and try again.

-----

Problem
After uploading a new APNs certificate, enrolled devices stop syncing and new devices cannot be enrolled.

Solution
This can occur if a new certificate was used instead of renewing the existing certificate. To resolve the problem, renew the certificate originally used andconfigure that in Intuneinstead. Note that if you have lost the credentials for the account used to obtain the original certificate, you may be able tocontact Applefor assistance, and give them the certificate GUID of certificate.

Let us know if you have any other questions by replying to thispostor reach out to @IntuneSuppTeam on Twitter - we’re happy to continue building out the FAQ!

Post Updates:

01/20/23: Updated Apple's support URLs based on customer feedback. Thanks for the feedback!

Intune and the APNs certificate: FAQ and common issues (2024)
Top Articles
Retik Finance Price, retik to USD, Research, News & Fundraising | Messari
Who is John McAfee? - Bitstamp Learn Center
Express Pay Cspire
How To Fix Epson Printer Error Code 0x9e
Www.1Tamilmv.cafe
123Movies Encanto
122242843 Routing Number BANK OF THE WEST CA - Wise
Cash4Life Maryland Winning Numbers
Identifont Upload
The Ivy Los Angeles Dress Code
Die Windows GDI+ (Teil 1)
Chase Claypool Pfr
Learn How to Use X (formerly Twitter) in 15 Minutes or Less
Pwc Transparency Report
Otr Cross Reference
Oxford House Peoria Il
Athens Bucket List: 20 Best Things to Do in Athens, Greece
Mephisto Summoners War
Busty Bruce Lee
Transfer Credits Uncc
Dexter Gomovies
[Birthday Column] Celebrating Sarada's Birthday on 3/31! Looking Back on the Successor to the Uchiha Legacy Who Dreams of Becoming Hokage! | NARUTO OFFICIAL SITE (NARUTO & BORUTO)
Saritaprivate
We Discovered the Best Snow Cone Makers for Carnival-Worthy Desserts
Graphic Look Inside Jeffrey Dahmer
Governor Brown Signs Legislation Supporting California Legislative Women's Caucus Priorities
California Online Traffic School
Beaufort 72 Hour
Enduring Word John 15
Ultra Ball Pixelmon
Vivification Harry Potter
Spirited Showtimes Near Marcus Twin Creek Cinema
Uky Linkblue Login
Kristen Hanby Sister Name
R3Vlimited Forum
Quality Tire Denver City Texas
Wow Quest Encroaching Heat
M3Gan Showtimes Near Cinemark North Hills And Xd
Marine Forecast Sandy Hook To Manasquan Inlet
The Blackening Showtimes Near Regal Edwards Santa Maria & Rpx
Raisya Crow on LinkedIn: Breckie Hill Shower Video viral Cucumber Leaks VIDEO Click to watch full…
Bbc Gahuzamiryango Live
Admissions - New York Conservatory for Dramatic Arts
1v1.LOL Game [Unblocked] | Play Online
Check From Po Box 1111 Charlotte Nc 28201
Wunderground Orlando
Acts 16 Nkjv
Craigslist Farm And Garden Reading Pa
Www Craigslist Com Atlanta Ga
Valls family wants to build a hotel near Versailles Restaurant
John M. Oakey & Son Funeral Home And Crematory Obituaries
Sara Carter Fox News Photos
Latest Posts
Article information

Author: Rev. Leonie Wyman

Last Updated:

Views: 6395

Rating: 4.9 / 5 (59 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Rev. Leonie Wyman

Birthday: 1993-07-01

Address: Suite 763 6272 Lang Bypass, New Xochitlport, VT 72704-3308

Phone: +22014484519944

Job: Banking Officer

Hobby: Sailing, Gaming, Basketball, Calligraphy, Mycology, Astronomy, Juggling

Introduction: My name is Rev. Leonie Wyman, I am a colorful, tasty, splendid, fair, witty, gorgeous, splendid person who loves writing and wants to share my knowledge and understanding with you.