Set up iOS and Mac device management

Nathan Barnett
Contributors

Intune mobile device management of iPads, iPhones, and Mac OS X devices and give access to company email and apps. An Apple Push Notification service (APNs) certificate is required for Intune to manage iOS and Mac devices. Once the certificate is added to Intune, users can install the Company Portal app to enroll their devices or the administrator can set up corporate-owned iOS device management.

  1. Set up Intune
    If you haven’t already, prepare for mobile device management by setting the mobile device management authority as Microsoft Intune and setting up MDM.

  2. Get a certificate signing request
    As an administrative user, open the Microsoft Intune administration console, go to Administration > Mobile Device Management > iOS and Mac OS X > Upload an APNs Certificate, and click Download the APNs certificate request. Save the certificate signing request (.csr) file locally. The .csr file is used to request a trust relationship certificate from the Apple Push Certificates Portal.

    Upload APNs certificate dialog box

  3. Get an Apple Push Notification service certificate
    Go to the Apple Push Certificates Portal and sign in with your company Apple ID to create the APNs certificate using the .csr file. After clicking Upload on Apple's Push Certificate Porta, you will receive a .json file which cannot be used for APNs. Complete the download and return to the Apple Push Certificates Portal for Certificates for Third-Party Servers and click Download.

    Download the APNs (.pem) certificate and save the file locally. This Apple ID must be used in future to renew your APNs certificate.

  4. Add the APNs certificate to Intune
    In the Microsoft Intune administration console, go to Administration > Mobile Device Management > iOS and Mac OS X > Upload an APNs Certificate, and click Upload the APNs certificate. Browse to the certificate (.pem) file and click Open and then enter your Apple ID. With the APNs certificate, Intune can enroll and manage iOS devices by pushing policy to enrolled mobile devices.

  5. Tell users how to get access to company resources with the company portal
    Your users will need to know how to enroll their devices and what to expect once they're brought into management. What to tell your end users about using Microsoft Intune

If your company or organization purchases iOS devices for users, those devices can also be enrolled for management as company-owned iOS devices.

See Also

Get ready to enroll devices in Microsoft Intune

To submit product feedback, please visit Intune Feedback