A Mac that was happily managed yesterday shows up today with no management profile, no policies and a user who swears they touched nothing. Microsoft documented exactly this on the Intune known issues page: a limited number of macOS devices were unexpectedly unenrolled because the MDM agent on the Mac mishandled a failed identity certificate installation during enrollment renewal. In this post I'll go through what Microsoft says about the cause and the fix, how to find the Macs that were hit, how to re-enroll them, and how to tell this apart from the much bigger problem of an expired Apple MDM push certificate.
Status (October 2026): Microsoft lists this issue on the Intune known issues page (last updated 30 March 2026 at the time of writing) with status Resolved; it was originally communicated in the Service Health Dashboard as IT393575. The fix is Apple's and shipped in macOS 26.4: if a new identity certificate fails to install during enrollment renewal, the original certificate is now kept so the device stays enrolled. Devices that already lost their enrollment still have to be re-enrolled. Re-check the official page for changes.
Symptoms#
- A managed Mac stops checking in. Its Intune record may still show as enrolled, because Intune doesn't learn about a locally removed profile straight away.
- On the Mac, System Settings › General › Device Management no longer shows the Intune management profile; the user didn't remove it.
- Configuration profiles, certificates, Wi-Fi and VPN settings delivered by Intune disappear; Conditional Access that requires a compliant device starts blocking the user.
- In some cases a brand-new enrollment fails outright rather than an existing one being removed.
Why it happens#
Microsoft's description is short and I'll stick to it. During MDM enrollment renewal the Mac installs a new identity certificate. Occasionally that installation failed, and the MDM agent handled the failure badly: when it didn't receive the headers it expected, the client removed its own MDM enrollment profile. The result is a device that is unmanaged from the Mac's point of view while Intune still believes it is enrolled. The problem is in the macOS MDM client, which is why the fix came from Apple in macOS 26.4 rather than from an Intune service change, and why Microsoft's only remediation for an affected device is to re-enroll it.
A related entry on the same page explains the reporting lag: when a management profile is deleted on an iOS/iPadOS or macOS device, the enrollment status in Intune may not update for up to 30 days. That's why "last check-in" is a far better signal than the enrollment state column.
How to fix it#
1. Get the remaining Macs to macOS 26.4 or later#
The resolution Microsoft points to is Apple's fix, so the first job is making sure every still-enrolled Mac moves to macOS 26.4 or later. Use your Intune macOS software update policy (Settings catalog or Declarative Device Management, depending on how you manage updates) and watch the OS version column under Devices › By platform › macOS.
2. Find the Macs that were hit#
In Devices › All devices, filter the OS to macOS, add the Last check-in column and sort ascending. Macs that stopped checking in abruptly while similar devices kept reporting are your candidates; export the list so you can compare it later. Cross-check with compliance: a device that silently dropped out usually drifts to a stale compliance state and triggers Conditional Access prompts, so your helpdesk tickets are a second data source. On a suspect Mac, Apple's profiles tool confirms the state from the terminal:
sudo profiles status -type enrollmentA Mac that has lost its enrollment reports MDM enrollment as No.
3. Re-enroll user-enrolled (Company Portal) Macs#
For Macs that were enrolled through the Company Portal app, the user re-enrolls themselves: open Company Portal (or install it from aka.ms/EnrollMyMac), sign in with their work account, follow the prompts, and approve the management profile when Company Portal opens System Settings. All Mac enrollments in Intune are treated as user-approved, and Intune turns on supervision automatically for macOS 11 and later, so the device comes back with the same management level it had.
4. Re-enroll Automated Device Enrollment Macs#
Macs purchased through Apple Business Manager or Apple School Manager normally enroll through Setup Assistant, and Microsoft's ADE guidance assumes a new or wiped device. The clean route is to erase the Mac and let it run Setup Assistant again, which picks up your enrollment policy over the air. Apple also documents a terminal command, sudo profiles renew -type enrollment, that re-triggers automated enrollment on a Mac that is already set up; test it on one device first, because the behaviour depends on the macOS version and on whether a user is signed in. If the device uses Setup Assistant with modern authentication, the user still has to sign in to Company Portal afterwards to finish Microsoft Entra registration.
5. Tidy the Intune records#
Re-enrollment usually creates a fresh device record while the stale one lingers until the 30-day lag or your device cleanup rules remove it. Once the new record is healthy, retire or delete the old one so compliance reports and dynamic groups stop counting a device that no longer exists.
Verify the fix#
On the Mac, System Settings › General › Device Management shows the management profile again and profiles status -type enrollment reports MDM enrollment as Yes. In Intune, the device shows a current last check-in, the expected OS version (26.4 or later), compliant status and the assigned profiles as Succeeded. Give it a day and confirm it is still there; the whole point of the fix is that the next enrollment renewal keeps the old identity certificate if the new one fails.
Related but different: the Apple MDM push certificate#
Admins sometimes blame this issue on the tenant's Apple MDM push certificate, and the two are easy to confuse because both end in Macs you can't manage. The push certificate is tenant-wide: it is what lets Intune talk to Apple's push service for every iOS/iPadOS and macOS device you manage, it is valid for 365 days, and Microsoft requires you to renew it annually with the same Apple account that created it. When it expires, Microsoft documents a 30-day grace period to renew. The difference in symptoms is scope: the macOS 26.x issue removed enrollment from a limited number of individual Macs at their own renewal time, while a push certificate problem affects all Apple devices at once and also stops new enrollments.
To renew: go to Devices › Device onboarding › Enrollment, open the Apple tab and select Apple MDM Push Certificate. Download the CSR, select Create your MDM push Certificate to open the Apple Push Certificates Portal, sign in with the original Apple ID, choose Renew on the existing certificate (not Create), upload the CSR, download the .pem, then back in Intune enter the Apple ID and upload the file. Renewal is complete when the certificate shows as active in both the admin center and Apple's portal. Microsoft's Intune for Education documentation spells out the consequence of getting this wrong: if you delete the certificate you must reset and re-enroll devices with a new one. Each certificate has a unique UID that appears as the Topic in the management profile on enrolled devices, which is why a renewed certificate keeps existing enrollments and a new one does not.
Watch out: Tenant administration › Tenant status › Connector status flags the push certificate as Warning seven days before expiry and Unhealthy once expired. Microsoft recommends a company mailbox monitored by more than one person as the Apple ID, never a personal one, and if you move to Managed Apple IDs you should ask Apple to migrate the existing certificate rather than start over.
Prevent it next time#
- Set a minimum macOS version in compliance policy and keep Macs on 26.4 or later; the fix only protects devices that have it.
- Report on Last check-in for macOS weekly; a sudden stop on a device whose peers are fine is the earliest signal you'll get.
- Put the Apple MDM push certificate, ADE token and VPP token expiry dates in a shared calendar and check Connector status monthly.
- Subscribe to Service health email notifications so the next IT-prefixed Intune advisory reaches you before the helpdesk does.