top of page
Search

Streamline Your Apple MDM Push Certificate Renewal with the Account Swap Method

šŸ” Seamless Renewal of Apple MDM Push Certificate Without Re‑Enrollment


Managing Apple devices via Intune often hinges on one critical component: the Apple Push Notification Service (APNs) certificate. This certificate acts as the trust anchor between Apple devices and Intune. But what happens when the Apple ID used to create the certificate — say, an employee’s account — is deleted? Traditionally, this would mean re‑enrolling every device, a nightmare for IT admins. Fortunately, there’s a smarter way.


🚧 The Challenge

  • The original Apple ID (xyz person’s account)Ā used to create the APNs certificate is deleted from IntuneĀ and Apple Business Manager (ABM).

  • Renewing the certificate with a new Apple ID normally breaks trust, forcing full re‑enrollment of all iPads/iPhones.

  • This disrupts applied policies, compliance, and app deployments.


āœ… The Solution: Account Swapping

Instead of re‑enrolling, you can swap the Apple IDĀ with a generic account across both Intune and ABM.


Step‑by‑Step Process


  1. Create a generic accountĀ in both IntuneĀ and Apple Business Manager.

    • Ensure the account name matchesĀ in both portals.

  2. Contact Apple Business Manager SupportĀ and request an account swap:

    • Ask them to replace the deleted xyz account with the new generic account.

  3. Once Apple confirms the swap:

    • Log in to IntuneĀ with the generic ID.

    • Navigate to Apple MDM Push Certificate.

    • Download the CSR (Certificate Signing Request).

    • Upload CSR to Apple Business Manager.

    • Renew the certificate and download the .pem file.

    • Return to Intune, upload the renewed certificate, and save.

šŸ‘‰ Result: The APNs certificate is renewed without breaking device trust. No re‑enrollment required.


šŸ“‹ Mandatory Information for Apple Support

Apple Business Manager will only process the swap if you provide:

  • Certificate Expiration Date

  • Certificate Serial Number

  • Current Apple Account IDĀ (xyz person’s account)

  • Target Apple Account IDĀ (generic account)


šŸ“‘ Documents Required

Prepare these before contacting Apple Support:

  1. Government‑issued ID

  2. Employee ID card

  3. Letter from Manager/HR confirming employment with your organization

  4. If managing client devices:

    • SOW (Statement of Work)

    • Agreement or client email confirming your role in managing Apple accounts/devices


āš ļø Without these documents, Apple will not approve the account swap.


šŸ›”ļø Why This Works

  • The APNs certificate is tied to the Apple ID identity.

  • By swapping the account, Apple ensures continuity of trust.

  • Devices continue to recognize Intune as the same MDM server, avoiding re‑enrollment.


šŸ“Š Quick Recap

Scenario

Device Trust

Policies & Apps

Admin Effort

Renew with same Apple ID

Maintained

Continue applying

Minimal

Create new certificate

Broken

Removed

Full re‑enrollment

Swap to generic account

Maintained

Continue applying

Moderate (docs + Apple support)


šŸŽÆ Key Takeaway

If the original Apple ID is deleted, don’t panic. By swapping to a generic accountĀ with Apple Business Manager support, you can renew the APNs certificate smoothly and keep all devices managed without downtime. You can use this method even if the account is not deleted,

Ā 
Ā 
Ā 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating

Disclaimer: The above content is created at Tek-Doyen's sole discretion. Razorpay shall not be liable for any content provided here and shall not be responsible for any claims and liability that may arise due to merchant’s non-adherence to it.

bottom of page