Important notes
It is important when dealing with Apple devices to keep an eye on the certificate renewal dates and to record them somewhere with a reminder. You could also use Azure Automation to automate the reminders for you. See more at https://andrewstaylor.com/2022/06/07/alerting-when-my-apple-certificates-expire-in-intune-using-azure-automation/.
The MDM push certificate connects your devices to the Intune MDM service. If this one expires, you can contact Apple directly within 30 days of expiry to renew it. If they cannot, or if 30 days have passed, your only option is to wipe and re-enroll all your devices. Yes, this is a full wipe, data destruction, everything.
An enrollment token is used to enroll your devices initially. If this one expires, you must create a new enrollment profile and transfer your devices to it. It is not quite as bad as a wipe, but it can result in the devices looking less healthy within the Intune portal itself.
The Apple VPP certificate is used...