You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Migrating MDM Push certificate to new ABM instance

Hi all.

I have two instance of ABM, lets call them ABM1 and ABM2.

ABM1 Apple Push Certificate was connected to Intune a few years ago. We have since migrated to a new instance of ABM (ABM2).

Is it possible to migrate the Apple Push Certificate to ABM2 so we dont need to re-enroll all Apple devices on the tenant?

Has anyone been though this process before? What was your experience if so?

iPhone 15

Posted on Jul 25, 2024 2:15 AM

Reply
3 replies

Jul 26, 2024 9:03 AM in response to NobelLemon

Going to try and help here.


You had business.apple.com (Apple Business Manager) setup for your organization and you used Intune as the MDM. Correct? Devices are still in Intune and actively being managed. In the process, you (1) created a Push Certificate and uploaded it to Intune, as well as (2) linked your DEP and VPP tokens to Intune for automatic device assignment and app deployment.


You now have a second business.apple.com (Apple Business Manager) for your new (?) business (?). What is your MDM? Is it still the same Intune instance? Are you moving to another


The reason for all these questions is that the Push certificate is installed in the MDM, not ABM. If this is an issue of the Apple ID used to create the Push certificate, then you likely need to talk to Apple about what to do here. I can envision you being painted into a corner in the following scenario: Your original ABM was linked to firstcompanyname.com and you created a managed Apple ID in ABM that you then used to obtain the Push cert. Now that you have another ABM linked to secondcompanyname.com, you are at risk of losing the original ABM or you the Apple ID used to obtain the Apple ID will no longer be accessible. This is a situation that is making my skin crawl.


If all you did was get a second ABM (for whatever reason, but I assume it is because you have a second business), then keep in mind that MDMs can support multiple DEP and VPP tokens. Just import into the existing MDM and keep going, using the original Apple ID to keep the push cert alive. If you are losing access to the Apple ID because the original ABM is being shutdown, then call this number and talk to Apple ABM support (assume you are in the US): 1-866-902-7144


See this article for numbers for other supported regions.


Also, did you move all your hardware assets from the original ABM to the new ABM? If so, then only during re-enrollment will there be the association from the new ABM.


Very curious as to why you have a second ABM tenant if you do not have a completely new company with a new DUNS.


Jul 29, 2024 1:44 AM in response to Strontium90

Hey, thanks for connecting!

The reason for multiple ABMs is a merger of two companies. I still have full access to both ABMs, ideally I we are going to decommission ABM1, which is where the push certificate was originally uploaded from. (Not talking about DEP or VPP at this point)

Is this anything you know of thats possible?

I'm UK based but Ill reach out to Apple ABM support also.

Migrating MDM Push certificate to new ABM instance

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.