PSA: Renewing your Intune Apple Tokens Annually (All 3 of them)
| Token / Cert Name | Apple Location | Intune Location |
| Apple Push Cert (User & Device Enrollment) | https://identity.apple.com/pushcert/ | Devices > Enroll Devices > Apple Enrollment > Apple MDM Push Certificate |
| Apple Enrollment Program (Apple Business Manager) | https://business.apple.com (Preferences > MDM Servers) | Devices > Enroll Devices > Apple Enrollment > Enrollment Program Tokens |
| Apple VPP Tokens (Books and Apps) | https://business.apple.com (Preferences > Payments and Billing) | Tenant Administration > Connectors and Tokens > Apple VPP Tokens |
Apple Push Cert Renewal (for all apple devices)
Renew the MDM push certificate with the same Apple account you used to create it.
- Sign in to the Microsoft Intune admin center.
- Select Devices > Enroll devices > Apple enrollment > Apple MDM Push Certificate.
- Select Download your CSR to download and save the request file locally. The file is used to request a trust relationship certificate from the Apple Push Certificates Portal.
- Navigate to https://identity.apple.com/pushcert/
- Find the certificate you want to renew and select Renew.
- Select Choose File and select the new CSR file you downloaded.
- Select Upload.
- On the Confirmation screen, select Download.
- Return to the admin center > Configure MDM Push Certificate page, and upload your certificate file that is in .pem format.
*Apple Push Cert- when it does expire, there is a 30 days grace period to renew.
Apple Enrollment Program Renewal (For supervised devices)
- Navigate to iOS/iPad OS enrollment under intune portal
- Select Enrollment program tokens and select the current token. Hit renew token
- Navigate to ABM (https://business.apple.com)
- In ABM, select the company below > preferences > under “Your MDM server” > download the token (.p7m file).
- You’ll upload this .p7m token under enrollment program tokens page on Intune.
Apple VPP Tokens (Books and Apps) (for BYOD or Corp devices)
- Navigate to Apple Business Manager or Apple School Manager.
- Download the existing token in Apple Business (or School) Manager, by selecting Preferences > Payments and Billing > Apps and Books > Server Tokens.
- Update the token in Microsoft Intune admin center by selecting Tenant administration > Connectors and tokens > Apple VPP tokens.
- Select the VPP token you are renewing, click Edit on the Basics category, upload the new token on this page, and then save your changes.
