Expired APNs certificate: re-enrolling Apple devices after creating a new APNs certificateSolved

Participant
Discussion
1 day ago Sep 06, 2026

Our APNs certificate expired a few months ago, and Apple said they can’t transfer it to another Apple ID because it has been expired for too long. I’m planning to generate a new APNs certificate in Hexnode using the preferred Apple ID.

I understand that this breaks the existing MDM trust, but I’m not clear on the re-enrollment process. Will the existing devices be deleted from Hexnode? Do users just reinstall the enrollment profile? Also, what happens to the old MDM profile already installed on iPhones, iPads, and Macs?

Replies (1)

Marked SolutionPending Review
Hexnode Expert
1 day ago Sep 06, 2026
Marked SolutionPending Review

If Apple cannot transfer the expired APNs certificate, you must create a new APNs certificate using the preferred Apple ID. Since the new certificate will not match the certificate originally used to enroll the devices, the existing MDM trust relationship is broken.

The existing device records will remain in the Hexnode portal, but Hexnode will no longer be able to send MDM commands, deploy policies, or manage those devices until they are enrolled again with the new APNs certificate.

To configure the new APNs certificate:

1. Go to Admin > APNs in the Hexnode portal.

2. Generate and download a new CSR.

3. Sign in to the Apple Push Certificates Portal with the preferred Apple ID.

4. Upload the CSR and download the new .pem certificate.

5. Upload the new APNs certificate back in Hexnode and save the changes.

After this, the devices must be re-enrolled.

Regards,

Mary Romero

Save