Use the same Apple ID that was used to create the original push certificate.
Renew the existing certificate — do NOT create a new certificate.
Creating a new one will break all enrolled devices.
Renewing must be done once per year before the expiration date.
Go to your MDM solution’s admin console (Jamf, Intune, Workspace ONE, etc.).
Navigate to where the Apple MDM Push Certificate is listed.
You will usually see:
The certificate’s expiration date
A Renew or Download CSR button
Click Renew (or Download CSR if required).
Your MDM will generate a file such as:
Save this file — you will upload it to Apple in the next step.
Visit:
Sign in using the exact same Apple ID that created the original certificate.
❗ If you use a different Apple ID, you will not see your existing certificate and risk breaking all devices.
Once logged in, you will see a list of all push certificates associated with that Apple ID.
Find the one matching:
Your MDM vendor name
The UID shown in your MDM console
The expiration date
Click Renew next to it.
Upload the CSR file you downloaded from your MDM system.
Apple will then generate a renewed file:
Download this file.
Return to your MDM admin console and upload the renewed .pem file.
Save/applies changes.
Your MDM should now show:
A new expiration date (one year later)
Status: Active
Devices will continue working with no interruption.