iPhones not checking in after APNs certificate expiredSolved

Participant
Discussion
4 weeks ago Jul 30, 2026

Several managed iPhones stopped checking in and apps are no longer installing from Hexnode. Some other devices still seem to be checking in normally.

The issue started after our team lost admin access for a while during an internal handover. After getting access back, we noticed the Apple devices were not syncing properly. It looks like the APNs certificate has expired.

Replies (3)

Marked SolutionPending Review
Hexnode Expert
4 weeks ago Jul 30, 2026
Marked SolutionPending Review

Hi @raelynn,

An expired APNs certificate will prevent Hexnode from communicating properly with managed Apple devices. This can cause symptoms such as iPhones not checking in, app installation commands not reaching devices, and remote actions staying pending.

If you still have access to the Apple ID used to create the original APNs certificate, renew the same certificate instead of creating a new one:

  1. Go to Admin > APNs in the Hexnode portal.
  2. Select Renew Certificate.
  3. Generate and download the CSR from Hexnode.
  4. Sign in to the Apple Push Certificates Portal using the same Apple ID that created the existing APNs certificate.
  5. Renew the existing certificate and upload the renewed certificate back to Hexnode.

It is important to renew the existing certificate with the original Apple Account. Creating a new APNs certificate with a different Apple Account establishes a new trust relationship, and the devices enrolled with the old APNs certificate will no longer be manageable through the existing enrollment.

Regards,
Sienna Carter
Hexnode UEM

Marked SolutionPending Review
Participant
4 weeks ago Jul 30, 2026
Marked SolutionPending Review

That is the issue in our case. The original Apple ID is not accessible anymore because it was tied to a previous admin. If we create a new APNs certificate with a different Apple ID, do all Apple devices need to be enrolled again? Also, will that wipe the devices?

Marked SolutionPending Review
Hexnode Expert
4 weeks ago Jul 30, 2026
Marked SolutionPending Review

Hi @raelynn,

If the original Apple Account cannot be recovered, you can create a new APNs certificate using another Apple Account, but the currently enrolled Apple devices must be re-enrolled.

The impact depends on the platform and enrollment method:

iOS/iPadOS devices enrolled through Apple Business or Apple Configurator: These devices generally need to be factory reset before they can be re-enrolled and associated with the new APNs certificate.
macOS devices: These do not necessarily need to be wiped. They can usually be re-enrolled using a Terminal-based enrollment command, so user data and local settings do not have to be erased solely for re-enrollment.

For iPhones and iPads, plan the re-enrollment carefully because a reset removes local data from the device. Any managed settings, apps, and restrictions can be reapplied after enrollment, but unmanaged local data should be backed up as appropriate before the reset.

Regards,
Sienna Carter
Hexnode UEM

Save