IntuneTroubleshooting

Macs unexpectedly unenrolled from Intune: the MDM certificate renewal issue and how to recover

Why some Macs dropped out of Intune during MDM identity certificate renewal, Apple's fix in macOS 26.4, how to find and re-enroll affected devices, and how this differs from an expired Apple MDM push certificate.

A Mac that was happily managed yesterday shows up today with no management profile, no policies and a user who swears they touched nothing. Microsoft documented exactly this on the Intune known issues page: a limited number of macOS devices were unexpectedly unenrolled because the MDM agent on the Mac mishandled a failed identity certificate installation during enrollment renewal. In this post I'll go through what Microsoft says about the cause and the fix, how to find the Macs that were hit, how to re-enroll them, and how to tell this apart from the much bigger problem of an expired Apple MDM push certificate.

How this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Related but different → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it (5 steps: Get the remaining Macs to macOS 26.4 or later; Find the Macs that were hit; Re-enroll user-enrolled (Company Portal) Macs; Re-enroll Automated Device Enrollment Macs; Tidy the Intune records). 4. Verify the fix. 5. Related but different. 6. Prevent it next time. Toolbox: General › Device Management, By platform › macOS, aka.ms/EnrollMyMac, Devices › All devices, Device onboarding › Enrollment.1Symptoms2Why it happens3How to fix it1Get the remainingMacs to macOS 2…2Find the Macs thatwere hit3Re-enrolluser-enrolled (Co…4Re-enrollAutomated Devic…5Tidy the Intunerecords4Verify the fix5Related but different6Prevent it next timeTOOLBOXGeneral › Device ManagementBy platform › macOSaka.ms/EnrollMyMacDevices › All devicesDevice onboarding › EnrollmentHow this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Related but different → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it (5 steps: Get the remaining Macs to macOS 26.4 or later; Find the Macs that were hit; Re-enroll user-enrolled (Company Portal) Macs; Re-enroll Automated Device Enrollment Macs; Tidy the Intune records). 4. Verify the fix. 5. Related but different. 6. Prevent it next time. Toolbox: General › Device Management, By platform › macOS, aka.ms/EnrollMyMac, Devices › All devices, Device onboarding › Enrollment.1Symptoms2Why it happens3How to fix it1Get the remaining Macs to macOS 26.4 or later2Find the Macs that were hit3Re-enroll user-enrolled (Company Portal) Macs4Re-enroll Automated Device Enrollment Macs5Tidy the Intune records4Verify the fix5Related but different6Prevent it next timeTOOLBOXGeneral › Device ManagementBy platform › macOSaka.ms/EnrollMyMacDevices › All devicesDevice onboarding › Enrollment
At a glance: how this guide is organised · 5 fix steps · 5 key tools

Status (October 2026): Microsoft lists this issue on the Intune known issues page (last updated 30 March 2026 at the time of writing) with status Resolved; it was originally communicated in the Service Health Dashboard as IT393575. The fix is Apple's and shipped in macOS 26.4: if a new identity certificate fails to install during enrollment renewal, the original certificate is now kept so the device stays enrolled. Devices that already lost their enrollment still have to be re-enrolled. Re-check the official page for changes.

Symptoms#

  • A managed Mac stops checking in. Its Intune record may still show as enrolled, because Intune doesn't learn about a locally removed profile straight away.
  • On the Mac, System Settings › General › Device Management no longer shows the Intune management profile; the user didn't remove it.
  • Configuration profiles, certificates, Wi-Fi and VPN settings delivered by Intune disappear; Conditional Access that requires a compliant device starts blocking the user.
  • In some cases a brand-new enrollment fails outright rather than an existing one being removed.

Why it happens#

Microsoft's description is short and I'll stick to it. During MDM enrollment renewal the Mac installs a new identity certificate. Occasionally that installation failed, and the MDM agent handled the failure badly: when it didn't receive the headers it expected, the client removed its own MDM enrollment profile. The result is a device that is unmanaged from the Mac's point of view while Intune still believes it is enrolled. The problem is in the macOS MDM client, which is why the fix came from Apple in macOS 26.4 rather than from an Intune service change, and why Microsoft's only remediation for an affected device is to re-enroll it.

A related entry on the same page explains the reporting lag: when a management profile is deleted on an iOS/iPadOS or macOS device, the enrollment status in Intune may not update for up to 30 days. That's why "last check-in" is a far better signal than the enrollment state column.

How to fix it#

1. Get the remaining Macs to macOS 26.4 or later#

The resolution Microsoft points to is Apple's fix, so the first job is making sure every still-enrolled Mac moves to macOS 26.4 or later. Use your Intune macOS software update policy (Settings catalog or Declarative Device Management, depending on how you manage updates) and watch the OS version column under Devices › By platform › macOS.

2. Find the Macs that were hit#

In Devices › All devices, filter the OS to macOS, add the Last check-in column and sort ascending. Macs that stopped checking in abruptly while similar devices kept reporting are your candidates; export the list so you can compare it later. Cross-check with compliance: a device that silently dropped out usually drifts to a stale compliance state and triggers Conditional Access prompts, so your helpdesk tickets are a second data source. On a suspect Mac, Apple's profiles tool confirms the state from the terminal:

Bash
sudo profiles status -type enrollment

A Mac that has lost its enrollment reports MDM enrollment as No.

3. Re-enroll user-enrolled (Company Portal) Macs#

For Macs that were enrolled through the Company Portal app, the user re-enrolls themselves: open Company Portal (or install it from aka.ms/EnrollMyMac), sign in with their work account, follow the prompts, and approve the management profile when Company Portal opens System Settings. All Mac enrollments in Intune are treated as user-approved, and Intune turns on supervision automatically for macOS 11 and later, so the device comes back with the same management level it had.

4. Re-enroll Automated Device Enrollment Macs#

Macs purchased through Apple Business Manager or Apple School Manager normally enroll through Setup Assistant, and Microsoft's ADE guidance assumes a new or wiped device. The clean route is to erase the Mac and let it run Setup Assistant again, which picks up your enrollment policy over the air. Apple also documents a terminal command, sudo profiles renew -type enrollment, that re-triggers automated enrollment on a Mac that is already set up; test it on one device first, because the behaviour depends on the macOS version and on whether a user is signed in. If the device uses Setup Assistant with modern authentication, the user still has to sign in to Company Portal afterwards to finish Microsoft Entra registration.

5. Tidy the Intune records#

Re-enrollment usually creates a fresh device record while the stale one lingers until the 30-day lag or your device cleanup rules remove it. Once the new record is healthy, retire or delete the old one so compliance reports and dynamic groups stop counting a device that no longer exists.

Verify the fix#

On the Mac, System Settings › General › Device Management shows the management profile again and profiles status -type enrollment reports MDM enrollment as Yes. In Intune, the device shows a current last check-in, the expected OS version (26.4 or later), compliant status and the assigned profiles as Succeeded. Give it a day and confirm it is still there; the whole point of the fix is that the next enrollment renewal keeps the old identity certificate if the new one fails.

Admins sometimes blame this issue on the tenant's Apple MDM push certificate, and the two are easy to confuse because both end in Macs you can't manage. The push certificate is tenant-wide: it is what lets Intune talk to Apple's push service for every iOS/iPadOS and macOS device you manage, it is valid for 365 days, and Microsoft requires you to renew it annually with the same Apple account that created it. When it expires, Microsoft documents a 30-day grace period to renew. The difference in symptoms is scope: the macOS 26.x issue removed enrollment from a limited number of individual Macs at their own renewal time, while a push certificate problem affects all Apple devices at once and also stops new enrollments.

To renew: go to Devices › Device onboarding › Enrollment, open the Apple tab and select Apple MDM Push Certificate. Download the CSR, select Create your MDM push Certificate to open the Apple Push Certificates Portal, sign in with the original Apple ID, choose Renew on the existing certificate (not Create), upload the CSR, download the .pem, then back in Intune enter the Apple ID and upload the file. Renewal is complete when the certificate shows as active in both the admin center and Apple's portal. Microsoft's Intune for Education documentation spells out the consequence of getting this wrong: if you delete the certificate you must reset and re-enroll devices with a new one. Each certificate has a unique UID that appears as the Topic in the management profile on enrolled devices, which is why a renewed certificate keeps existing enrollments and a new one does not.

Watch out: Tenant administration › Tenant status › Connector status flags the push certificate as Warning seven days before expiry and Unhealthy once expired. Microsoft recommends a company mailbox monitored by more than one person as the Apple ID, never a personal one, and if you move to Managed Apple IDs you should ask Apple to migrate the existing certificate rather than start over.

Prevent it next time#

  • Set a minimum macOS version in compliance policy and keep Macs on 26.4 or later; the fix only protects devices that have it.
  • Report on Last check-in for macOS weekly; a sudden stop on a device whose peers are fine is the earliest signal you'll get.
  • Put the Apple MDM push certificate, ADE token and VPP token expiry dates in a shared calendar and check Connector status monthly.
  • Subscribe to Service health email notifications so the next IT-prefixed Intune advisory reaches you before the helpdesk does.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)