You are here: Home > Device Management > Apple > Renew the Apple Push Certificate

Renewing Without Losing Your Fleet

Renew your Apple Push Certificate with the account that created it, and find out which Apple ID that was when nobody remembers.

4 min read

TL;DR

Renew with the same Apple ID that created the certificate. A different account means losing control of every enrolled Device.

The Apple Push Certificate is what lets Applivery talk to your Apple Devices. It expires every year, and renewing it is routine — as long as you renew it with the account that created it.

Warning

The certificate must be renewed with the same Apple ID that created it. Signing in with a different account does not renew your certificate: it creates a separate one. The original expires, Applivery stops being able to manage your enrolled Devices, and getting them back means re-enrolling the entire fleet.

For the initial setup, see Get Started.

Finding out which Apple ID was used

If the Apple ID field was filled in during setup, the account is recorded in your Workspace, under Settings → Apple Setup. That is the whole point of the field.

If it was left empty, Applivery has no record of it. The account lives only on Apple's side, so it has to be identified from outside the platform:

  • Old emails from Apple. Receipts, renewal notices and expiry warnings all go to the account that owns the certificate. Search the shared mailboxes too, not just personal ones.

  • Whoever set up the MDM originally. Often an administrator who has since changed role or left, so it is worth asking beyond the current IT team.

  • The Apple Push Certificates Portal. Sign in with each corporate account you suspect and check whether the certificate is listed. The account that shows it is the owner.

If none of that works, contact Apple Support. The certificate belongs to the Apple ID that created it, and Applivery cannot transfer or recover it.

Checking you are renewing the right certificate

Before you renew, confirm that the certificate identifier shown in Applivery matches the one in the Apple Push Certificates Portal. If they differ, you are looking at two different certificates — and renewing the wrong one leaves the real one to expire on schedule.

Preventing it next year

Fill in the Apple ID field in your Workspace. It costs one minute during setup, it records the account where the next administrator will look for it, and it is the difference between a routine renewal and re-enrolling every Device you manage.

Key Takeaways

  • The certificate must be renewed with the Apple ID that created it.
  • A different Apple ID means losing control of enrolled Devices.
  • Applivery only knows the account if the Apple ID field was filled in.
  • Check the certificate identifier matches before renewing.
  • Filling in the Apple ID field is the cheapest prevention available.

Yes, always. Renewing with a different Apple ID creates a new certificate instead of renewing yours, and you lose control of every enrolled Device.

Applivery can no longer talk to your enrolled Devices. Recovering them means re-enrolling the whole fleet.

If the Apple ID field was filled in your Workspace, it is there. If it was not, Applivery has no record of it and you have to identify it outside the platform.

Look for old Apple emails with receipts or renewal notices, ask whoever set up the MDM originally, or try your corporate accounts in the Apple Push Certificates Portal to see which one lists the certificate.

Contact Apple Support. It is the only remaining route, since the certificate belongs to the Apple ID that created it.

It usually means you are looking at a different certificate. Check which one matches before renewing, or you may renew the wrong certificate and leave the real one to expire.

Annually. Renew it before the expiry date, not after.

Yes. Fill in the Apple ID field in your Workspace, so the account is recorded where the next administrator will look for it.

Was this page helpful?

Last updated: September 11, 2026