Regards with the MDM CA

Krishnakumar Bojarajan 0 Reputation points
2025-11-10T05:48:12.1533333+00:00

Hi All ,

Could you please let me know. should i need to renew my Intune MDM CA certificate manually after the expiry or it automatically renews ?

Let me know the solution for this !

Microsoft Security | Intune | Updates
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Diana Mariz 4,130 Reputation points Independent Advisor
    2025-11-10T07:33:09.87+00:00

    Hi,

    Regarding your question about Intune MDM CA certificates: for Windows devices, Intune supports automatic renewal of MDM client certificates, so you generally do not need to take manual action when they are about to expire.

    However, if your environment also manages iOS or macOS devices, the Apple MDM Push certificate used for those devices must be renewed manually before it expires. Failing to do so will cause all managed Apple devices to stop receiving MDM commands.

    So, automatic renewal applies to Windows, but for Apple devices, manual intervention is required to ensure uninterrupted device management.

    For more information, you can refer to this link: https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/mdm-authority-set#coexistence and https://learn.microsoft.com/en-us/windows/client-management/certificate-renewal-windows-mdm

    1 person found this answer helpful.

  2. Diana Mariz 4,130 Reputation points Independent Advisor
    2025-11-10T07:55:40.46+00:00

    You are most welcome, I am glad to help and provide clarification! If further assistance needed in the future, please don't hesitate to reach out and we would be more than happy to help you.

    1 person found this answer helpful.
    0 comments No comments

  3. Q&A Assist
    2025-11-10T05:48:25.1033333+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    In the context of Intune MDM, the renewal of the MDM CA certificate can occur automatically when mobile devices communicate with the Intune service. However, if mobile devices are wiped or fail to communicate with the Intune service for a certain period, the MDM certificate may not be renewed automatically. In such cases, you may need to manage the renewal process manually after the certificate expires.

    To ensure continuous access to enterprise applications, it is recommended to set a renewal period a couple of months before the certificate expires and configure the device for automatic renewal if possible.


    References:


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.