取得 Apple MDM Push CertificateGet an Apple MDM push certificate

Intune 可啟用 iPad、iPhone 和 Mac 電腦的行動裝置管理 (MDM),且可提供使用者對公司電子郵件和應用程式的存取。Intune enables mobile device management (MDM) of iPads, iPhones, and Mac computers and gives users access to company email and apps. 必須要有 Apple MDM Push Certificate,Intune 才能管理 iOS 和 macOS 裝置。An Apple MDM Push certificate is required for Intune to manage iOS and macOS devices. 將憑證新增至 Intune 之後,使用者即可使用下列方式來註冊其裝置:After you add the certificate to Intune, your users can enroll their devices using:

  • 公司入口網站應用程式。The Company Portal app.

  • Apple 的大量註冊方法,例如「裝置登記方案」、Apple School Manager 或 Apple Configurator。Apple's bulk enrollment methods like the Device Enrollment Program, Apple School Manager, or Apple Configurator.

如需有關註冊選項的詳細資訊,請參閱選擇如何註冊 iOS 裝置For more information about enrollment options, see Choose how to enroll iOS devices.

當 Push Certificate 到期時,您必須更新它。When a push certificate expires, you must renew it. 進行更新時,請務必使用您最初建立 Push Certificate 時所使用的相同 Apple ID。When renewing, make sure to use the same Apple ID that you used when you first created the push certificate.

取得憑證的步驟Steps to get your certificate

Azure 入口網站中,選擇 [裝置註冊] > [Apple 註冊] > [Apple MDM Push Certificate],然後在 Azure 入口網站中遵循下列步驟進行。In the Azure portal, choose Device enrollment > Apple Enrollment > Apple MDM Push Certificate, and then follow these steps in the Azure portal.

步驟 1:Step 1. 將權限授與 Microsoft 以將使用者和裝置資訊傳送給 AppleGrant Microsoft permission to send user and device information to Apple

選取 [我同意]Select I agree. 來將權限授與 Microsoft,以將資料傳送給 Apple。to give Microsoft permission to send data to Apple.

未設定 MDM Push 的 [設定 MDM Push Certificate] 畫面。

步驟 2:Step 2. 下載建立 Apple MDM Push Certificate 所需的 Intune 憑證簽署要求Download the Intune certificate signing request required to create an Apple MDM push certificate

選取 [下載您的 CSR],在本機下載並儲存要求檔案。Select Download your CSR to download and save the request file locally. 該檔案可用來向 Apple Push Certificates 入口網站要求信任關係憑證。The file is used to request a trust relationship certificate from the Apple Push Certificates Portal.

步驟 3:Step 3. 建立 Apple MDM Push CertificateCreate an Apple MDM push certificate

選取 [建立您的 MDM Push Certificate],以前往 Apple Push Certificates 入口網站。Select Create your MDM push Certificate to go to the Apple Push Certificates Portal. 使用您的公司 Apple ID 登入,然後按一下 [建立憑證]。Sign in with your company Apple ID, and then click Create a Certificate. 選取 [選擇檔案],然後瀏覽至憑證簽署要求檔案,然後選擇 [上傳]。Select Choose File and browse to the certificate signing request file, and then choose Upload. 在 [確認] 頁面上,選取 [下載] 以下載憑證檔案 (.pem),然後將檔案儲存在本機。On the Confirmation page, choose Download to the download the certificate (.pem) file, and save the file locally.

注意

憑證會建立與用來建立憑證之 Apple ID 的關聯。The certificate is associated with the Apple ID used to create it. 最佳做法是使用管理工作的公司 Apple ID,並確定信箱由多人監視,例如通訊群組清單。As a best practice, use a company Apple ID for management tasks and make sure the mailbox is monitored by more than one person like a distribution list. 請不要使用個人 Apple ID。Never use a personal Apple ID.

步驟 4:Step 4. 輸入用以建立 Apple MDM Push Certificate 的 Apple IDEnter the Apple ID used to create your Apple MDM push certificate

請記錄此識別碼,以在需要更新此憑證時提醒您。Record this ID as a reminder for when you need to renew this certificate.

步驟 5:Step 5. 瀏覽至要上傳的 Apple MDM Push CertificateBrowse to your Apple MDM push certificate to upload

前往憑證 (.pem) 檔案,選擇 [開啟],然後選擇 [上傳]。Go to the certificate (.pem) file, choose Open, and then choose Upload. Intune 可利用推播憑證,註冊及管理 Apple 裝置。With the push certificate, Intune can enroll and manage Apple devices.

更新 Apple MDM Push CertificateRenew Apple MDM push certificate

Apple MDM Push Certificate 有效期限為一年,必須每年更新以維護 iOS 及 macOS 裝置管理。The Apple MDM push certificate is valid for one year and must be renewed annually to maintain iOS and macOS device management. 如果您的憑證過期,即無法連絡註冊的 Apple 裝置。If your certificate expires, enrolled Apple devices cannot be contacted.

憑證會與用來建立憑證的 Apple ID 相關。The certificate is associated with the Apple ID used to create it. 請以用於建立 MDM Push Certificate 的同一個 Apple ID 予以更新。Renew the MDM push certificate with the same Apple ID used to create it.

  1. Azure 入口網站中,選擇 [裝置註冊] > [Apple 註冊],然後選擇詳細資料區域的 [Apple MDM Push Certificate] 磚。In the Azure portal, choose Device enrollment > Apple Enrollment, and then choose the Apple MDM Push Certificate tile in the details area.

  2. 選擇 [下載您的 CSR],在本機下載並儲存要求檔案。Choose Download your CSR to download and save the request file locally. 該檔案可用來向 Apple Push Certificates 入口網站要求信任關係憑證。The file is used to request a trust relationship certificate from the Apple Push Certificates Portal.

  3. 選取 [建立您的 MDM Push Certificate],以前往 Apple Push Certificates 入口網站。Select Create your MDM push Certificate to go to the Apple Push Certificates Portal. 尋找您想要更新的憑證,並選取 [更新]。Find the certificate you want to renew and select Renew.

  4. 在 [更新 Push Certificate] 畫面上,提供附註以協助您在未來識別憑證,選取 [選擇檔案] 以瀏覽至您下載的新要求檔案,然後選擇 [上傳]。On the Renew Push Certificate screen, provide notes to help you identify the certificate in the future, select Choose File to browse to the new request file you downloaded, and choose Upload.

    提示

    可由其 UID 識別憑證。A Certificate can be identified by its UID. 檢查憑證詳細資料的主體識別碼,尋找 UID 的 GUID 部分。Examine the Subject ID in the certificate details to find the GUID portion of the UID. 或者,在已註冊的 iOS 裝置上移至 [設定] > [一般] > [裝置][管理] > [管理設定檔] > [詳細資料] > [管理設定檔]。Or, on an enrolled iOS device, go to Settings > General > Device Management > Management Profile > More Details > Management Profile. 第二個明細項目 [主題],包含可與 Apple Push Certificates 入口網站憑證比對的唯一 GUID。The second line item, Topic, contains the unique GUID that you can match up to the certificate in the Apple Push Certificates portal.

  5. 在 [確認] 畫面上,選取 [下載] 並將 .pem 檔案儲存於本機。On the Confirmation screen, select Download and save the .pem file locally.

  6. Azure 入口網站中,選取 Apple MDM Push Certificate 瀏覽圖示,並選取從 Apple 下載的 .pem 檔案,然後選擇 [上傳]。In the Azure portal, select the Apple MDM push certificate browse icon, select the .pem file downloaded from Apple, and choose Upload.

您的 Apple MDM Push Certificate 會顯示為 [使用中],距離到期還有 365 天。Your Apple MDM push certificate appears Active and has 365 days until expiration.