MDM Push Certificate Apple ID Change

Justin Lee 221 Reputation points
2022-08-22T19:05:09.593+00:00

I found an old question regarding this, but was nearly 8 years old.

We have Macs and iOS devices, but the MDM Push Certificate was setup with a personal Apple ID. We need to change this asap with minimal effect to end users. What is the best practice here? Impact?

Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,485 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,570 questions
{count} votes

Accepted answer
  1. Jason Sandys 31,411 Reputation points Microsoft Employee
    2022-08-22T20:01:13.227+00:00

    Contact Apple as only they can help you with this. Normally, swapping out the MDM cert requires all Apple devices to be reenrolled as the MDM profile is linked to the cert. This is all Apple device management specific and not related to Intune.


6 additional answers

Sort by: Most helpful
  1. Mark Jorissen 1 Reputation point
    2023-01-05T13:10:11.51+00:00

    Look at https://learn.microsoft.com/en-us/mem/intune/enrollment/device-enrollment-program-enroll-ios#renew-an-automated-device-enrollment-token

    Perhaps this document can help you a little bit.

    We're facing a similar problem. Token used AppleID from somebody who's going to leave the company. Not sure if we could renew the whole thing with another AppleID without re-enrolling devices...


  2. Mark Jorissen 1 Reputation point
    2023-01-24T12:31:53.6933333+00:00

    How can I see dat we've got federation configured?

    To be clear, I can see the Apple VPP Token at Home - Tenant admin - Connectors and tokens - Apple VPP Tokens.

    There is the AppleID, Token Name, and Status which says: Assigned to external MDM (Which is Jamf). Properties also says: assignedToExternalMDM

    Also at Home - Devices - iOS/iPAdOS enrollment i can see this token where the same ID is used:

    about 59 devices are enrolled with this token/apple id...

    User's image

    I am fairly new to this... These kind of things you do only once in Azure....

    0 comments No comments

  3. Mark Jorissen 1 Reputation point
    2023-01-24T13:11:35.0033333+00:00

    Hi Jose, How can we check if federation is used?

    Justin, would like to know the steps: here are some screenshots:

    So it's about changing the appleid. We have got another AppleID in Buissiness manager which we can use.

    About 59 devs are enrolled using the token...

    User's image

    User's image


  4. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.