Important notes
When dealing with Apple devices, there are some very important things to consider throughout the initial setup and continued management, which we will run through here.
It is important when dealing with Apple devices to keep an eye on the certificate renewal dates and record them somewhere, with a renewal reminder. You could also use Azure Automation to automate the reminders for you; see more here: https://andrewstaylor.com/2022/06/07/alerting-when-my-apple-certificates-expire-in-intune-using-azure-automation/.
The MDM Push Certificate connects your devices to the Intune MDM Service. If this expires, you can sometimes contact Apple directly if it is within 30 days of expiry to renew it. If they cannot, or 30 days have passed, your only option is to wipe and re-enroll all your devices. Yes, it is a full wipe – data destruction, everything.
The enrollment token is used to initially enroll your devices. If this expires, you must create a new enrollment...