Streamline Your Apple MDM Push Certificate Renewal with the Account Swap Method
- Tek Doyen

- Jul 9
- 2 min read
š Seamless Renewal of Apple MDM Push Certificate Without ReāEnrollment
Managing Apple devices via Intune often hinges on one critical component: the Apple Push Notification Service (APNs) certificate. This certificate acts as the trust anchor between Apple devices and Intune. But what happens when the Apple ID used to create the certificate ā say, an employeeās account ā is deleted? Traditionally, this would mean reāenrolling every device, a nightmare for IT admins. Fortunately, thereās a smarter way.
š§ The Challenge
The original Apple ID (xyz personās account)Ā used to create the APNs certificate is deleted from IntuneĀ and Apple Business Manager (ABM).
Renewing the certificate with a new Apple ID normally breaks trust, forcing full reāenrollment of all iPads/iPhones.
This disrupts applied policies, compliance, and app deployments.
ā The Solution: Account Swapping
Instead of reāenrolling, you can swap the Apple IDĀ with a generic account across both Intune and ABM.
StepābyāStep Process
Create a generic accountĀ in both IntuneĀ and Apple Business Manager.
Ensure the account name matchesĀ in both portals.
Contact Apple Business Manager SupportĀ and request an account swap:
Ask them to replace the deleted xyz account with the new generic account.
Once Apple confirms the swap:
Log in to IntuneĀ with the generic ID.
Navigate to Apple MDM Push Certificate.
Download the CSR (Certificate Signing Request).
Upload CSR to Apple Business Manager.
Renew the certificate and download the .pem file.
Return to Intune, upload the renewed certificate, and save.
š Result: The APNs certificate is renewed without breaking device trust. No reāenrollment required.
š Mandatory Information for Apple Support
Apple Business Manager will only process the swap if you provide:
Certificate Expiration Date
Certificate Serial Number
Current Apple Account IDĀ (xyz personās account)
Target Apple Account IDĀ (generic account)
š Documents Required
Prepare these before contacting Apple Support:
Governmentāissued ID
Employee ID card
Letter from Manager/HR confirming employment with your organization
If managing client devices:
SOW (Statement of Work)
Agreement or client email confirming your role in managing Apple accounts/devices
ā ļø Without these documents, Apple will not approve the account swap.
š”ļø Why This Works
The APNs certificate is tied to the Apple ID identity.
By swapping the account, Apple ensures continuity of trust.
Devices continue to recognize Intune as the same MDM server, avoiding reāenrollment.
š Quick Recap
Scenario | Device Trust | Policies & Apps | Admin Effort |
Renew with same Apple ID | Maintained | Continue applying | Minimal |
Create new certificate | Broken | Removed | Full reāenrollment |
Swap to generic account | Maintained | Continue applying | Moderate (docs + Apple support) |
šÆ Key Takeaway
If the original Apple ID is deleted, donāt panic. By swapping to a generic accountĀ with Apple Business Manager support, you can renew the APNs certificate smoothly and keep all devices managed without downtime. You can use this method even if the account is not deleted,





Comments