Skip to content

Commit 72ce048

Browse files
authored
Update apple-mdm-push-certificate-get.md
Added contributions to Renew section. Brief clean-up of intro.
1 parent 5422e1a commit 72ce048

1 file changed

Lines changed: 12 additions & 9 deletions

File tree

memdocs/intune/enrollment/apple-mdm-push-certificate-get.md

Lines changed: 12 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -35,15 +35,14 @@ ms.collection:
3535

3636
[!INCLUDE [azure_portal](../includes/azure_portal.md)]
3737

38-
An Apple MDM Push certificate is required for Intune to manage iOS/iPadOS and macOS devices. After you add the certificate to Intune, your users can enroll their devices using:
38+
Upload and renew your Apple MDM push certificates in Microsoft Intune. An Apple MDM Push certificate is required to manage iOS/iPadOS and macOS devices in Microsoft Intune, and enables devices to enroll via:
3939

40-
- The Company Portal app.
40+
- The Intune Company Portal app
41+
- Apple bulk enrollment methods, such as the Device Enrollment Program, Apple School Manager, and Apple Configurator
4142

42-
- Apple's bulk enrollment methods like the Device Enrollment Program, Apple School Manager, or Apple Configurator.
43+
Certificates must be renewed annually.
4344

44-
For more information about enrollment options, see [Choose how to enroll iOS/iPadOS devices](ios-enroll.md).
45-
46-
When a push certificate expires, you must renew it within the grace period (30 days as of this writing). When renewing, make sure to use the same Apple ID that you used when you first created the push certificate.
45+
This article describes how to use Intune to create and renew an Apple MDM push certificate.
4746

4847

4948
## Steps to get your certificate
@@ -73,18 +72,22 @@ Record this ID as a reminder for when you need to renew this certificate.
7372
Go to the certificate (.pem) file, choose **Open**, and then choose **Upload**. With the push certificate, Intune can enroll and manage Apple devices.
7473

7574
## Renew Apple MDM push certificate
76-
The Apple MDM push certificate is valid for one year and must be renewed annually to maintain iOS/iPadOS and macOS device management. If your certificate expires, enrolled Apple devices cannot be contacted.
75+
The Apple MDM push certificate is valid for one year. You must renew it annually to maintain iOS/iPadOS and macOS device management. Once the certificate expires, there is a 30-day grace period to renew it.
7776

78-
The certificate is associated with the Apple ID used to create it. Renew the MDM push certificate with the same Apple ID used to create it.
77+
Renew the MDM push certificate with the same Apple ID you used to create it.
7978

8079
1. Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), choose **Devices** > **Enroll devices** > **Apple enrollment** > **Apple MDM Push Certificate**.
8180
2. Choose **Download your CSR** to download and save the request file locally. The file is used to request a trust relationship certificate from the Apple Push Certificates Portal.
8281
3. Select **Create your MDM push Certificate** to go to the Apple Push Certificates Portal. Find the certificate you want to renew and select **Renew**.
8382
4. On the **Renew Push Certificate** screen, provide notes to help you identify the certificate in the future, select **Choose File** to browse to the new request file you downloaded, and choose **Upload**.
8483
> [!TIP]
85-
> A Certificate can be identified by its UID. Examine the **Subject ID** in the certificate details to find the GUID portion of the UID. Or, on an enrolled iOS/iPadOS device, go to **Settings** > **General** > **Device** **Management** > **Management Profile** > **More Details** > **Management Profile**. The second line item, **Topic**, contains the unique GUID that you can match up to the certificate in the Apple Push Certificates portal.
84+
> A certificate can be identified by its UID. Examine the **Subject ID** in the certificate details to find the GUID portion of the UID. Or, on an enrolled iOS/iPadOS device, go to **Settings** > **General** > **Device** **Management** > **Management Profile** > **More Details** > **Management Profile**. The second line item, **Topic**, contains the unique GUID that you can match up to the certificate in the Apple Push Certificates portal.
8685
8786
6. On the **Confirmation** screen, select **Download** and save the .pem file locally.
8887
7. In [Intune](https://go.microsoft.com/fwlink/?linkid=2090973), select the **Apple MDM push certificate** browse icon, select the .pem file downloaded from Apple, and choose **Upload**.
8988

9089
Your Apple MDM push certificate appears **Active** and has 365 days until expiration.
90+
91+
## Next steps
92+
93+
For more information about enrollment options, see [Choose how to enroll iOS/iPadOS devices](ios-enroll.md).

0 commit comments

Comments
 (0)