APNS Certificates
Last Updated: May 2025
Implementation Effort: Low – The process involves a one-time setup and annual renewal, requiring targeted administrative actions without ongoing project work.
User Impact: Low – End users are not directly involved; the certificate enables background device management functionality.
Introduction
Apple Push Notification Service (APNS) certificates are a foundational requirement for managing macOS devices with Intune. Without a valid APNS certificate, Intune cannot communicate with Apple devices, making it impossible to enforce compliance policies, deploy configurations, or manage apps. This section helps macOS administrators ensure their APNS setup is secure, current, and aligned with Zero Trust principles.
This guidance applies to both new Intune environments and existing deployments that need to validate or renew their APNS configuration.
Why This Matters
- Enables device management: APNS is required for Intune to push policies, apps, and commands to macOS devices.
- Supports Zero Trust enforcement: Without APNS, compliance and Conditional Access policies cannot be enforced.
- Prevents management disruption: An expired or misconfigured APNS certificate will break device communication.
- Ensures continuity: A valid APNS certificate is essential for ongoing policy evaluation and trust verification.
Key Considerations
What APNS Does
- Acts as a secure channel between Intune and Apple devices.
- Required for all MDM actions, including policy deployment, remote commands, and compliance checks.
Certificate Requirements
- You must obtain an APNS certificate from Apple using a verified Apple ID.
- The certificate is valid for one year and must be renewed before expiration to avoid service disruption.
- The same Apple ID must be used for renewals to maintain continuity.
Initial Setup
- In the Intune admin center, navigate to:
Devices > macOS > macOS enrollment > Apple MDM Push certificate - Download the CSR (certificate signing request) and upload it to the Apple Push Certificates Portal.
- Download the signed certificate and upload it back into Intune.
Renewal Process
- Set calendar reminders or use automation to track expiration dates.
- Renew the certificate using the same Apple ID used during initial setup.
- Validate that devices remain connected after renewal.