5 min readMicrosoft Intune · Apple · MSP · Best Practices
Apple push certificate, VPP and ADE tokens in Intune: tracking expiry across every tenant
Three Apple connections in Intune expire every year. What happens when they do, what to watch for when you renew them, and how SecretExpiry monitors their expiry dates across all customer tenants.
If you manage iPhones, iPads and Macs with Intune, you depend on three connections to Apple: the Apple MDM push certificate, the VPP token for purchased apps and the token for automated device enrollment (ADE). Each is valid for 365 days. When one of them runs out, the first to notice is often a user whose device stops receiving policies, or a colleague whose new MacBook no longer enrolls itself on first start.
The Apple MDM push certificate
Intune reaches managed Apple devices through the Apple Push Notification service. The device gets a nudge and then fetches policies, apps and commands. The certificate behind this connection is valid for 365 days. According to Microsoft, you have a 30-day grace period after expiry to renew it. After that, Intune can no longer manage the devices that enrolled with this certificate.
The part that matters most when renewing is the Apple ID. The certificate has to be renewed with the same Apple account that created it. Use a different one and you get a new certificate, and every device has to enroll again. For a customer with 80 iPhones, that is 80 re-enrollments.
The renewal itself is short: in the Intune admin center under "Devices > Device onboarding > Enrollment > Apple > Apple MDM Push Certificate" you download a certificate signing request (CSR), renew the existing certificate with that file in the Apple Push Certificates Portal and upload the result back to Intune.
The VPP token
The VPP token connects Intune to the apps and books purchased in Apple Business Manager or Apple School Manager. Through the token, Intune assigns licenses and installs apps without the user needing an Apple ID of their own. This token is valid for 365 days as well. Once it expires, Intune lists it as "invalid". The same happens when the domain of the managed Apple ID changes, its password is changed or expires, or the account is disabled.
One dependency is easy to miss. If an automated device enrollment profile deploys the Company Portal app through a VPP token, Microsoft states that Intune blocks new devices from enrolling once that token expires.
To renew it, download the token again in Apple Business Manager or Apple School Manager under "Preferences > Payments and Billing > Apps and Books > Content Tokens" and upload it in Intune under "Tenant administration > Connectors and tokens > Apple VPP tokens" on the existing token. The new expiry date can take a while to show up in Intune.
The ADE token
The automated device enrollment token (formerly DEP) connects Intune to an MDM server in Apple Business Manager or Apple School Manager. Through it, Intune learns which serial numbers are assigned to the organization, and new devices enroll themselves on first start. You have to renew this token every year. Without a renewal, Microsoft says, changes from Apple Business Manager no longer reach Intune, and that includes newly assigned devices.
Renewing has one trap: downloading a new token in Apple Business Manager already invalidates the old one. Once you start the download, finish the upload in Intune right away. There you select the token under "Enrollment program tokens", choose "Renew token" and enter the Apple ID that created the original token. Unlike with the push certificate, switching the Apple ID only affects enrolled devices when they enroll again.
Why the dates still slip
The Intune admin center shows all three expiry dates, and according to Microsoft, Intune flags tokens that are about to expire there. That works as long as someone opens the admin center regularly. An MSP with 30 customer tenants would have to check 30 admin centers. Then there is the Apple ID: often a colleague created the certificate a year ago, and nobody wrote down which account was used.
An obvious workaround is one script per customer, for example an Azure Automation runbook that reads the expiry dates through Microsoft Graph and sends a mail. That holds for a while. But every one of these scripts needs an identity that is allowed to read Microsoft Graph. If it signs in with a client secret or certificate, that expires too and has to be renewed. And if the secret sits in the script itself, anyone who can open the runbook can read it.
How SecretExpiry monitors the Apple objects
SecretExpiry reads the push certificate, the VPP tokens and the ADE tokens of every actively monitored tenant once a day through Microsoft Graph. For this, the app additionally needs the read-only application permission DeviceManagementServiceConfig.Read.All ("Read Microsoft Intune configuration"). For tenants that are already connected, select "Renew permissions" on the tenant page; an admin of the customer tenant then confirms the extended consent. How admin consent works in detail is covered in Admin consent in Microsoft Entra explained for MSPs.
In the dashboard, the three objects appear as their own app "Microsoft Intune" next to the tenant's app registrations, with an "Intune" filter in the credential table and a link straight into the Intune admin center. The same thresholds apply as for client secrets, by default 90, 30, 14, 7 and 1 day before expiry, and the same channels: e-mail per event or as a weekly digest, Teams or Slack via webhook, and the calendar feed. The mail names the right renewal path for each type, so for the push certificate it reminds you to use the same Apple ID. The Apple ID itself is shown in the entry's detail view, so you do not have to search for it when renewing. It does not appear in mails, webhooks, CSV exports or the calendar.
What is stored is the ID, the name, the expiry date and the Apple ID. SecretExpiry does not request the certificate itself. Should Microsoft Graph include the value of a VPP token in its response, it is discarded on read.
Microsoft offers the ADE tokens in the beta version of Microsoft Graph only. If the response format changes there, the tenant page shows an Intune error and the last expiry dates read stay in place. If the Intune read stays incomplete for a week while the tenant still has Apple entries on record, a single warning mail goes out.
The trial is free for 14 days; after that SecretExpiry starts at 10 € per tenant per month. Setup is described in the docs.