Skip to content
Avanet

Sophos Mobile: Match and renew the APNs certificate safely

The steps below require checking the prerequisites and certificate identity in the specific tenant; they do not establish that a certificate renewal has succeeded on any tenant or device. Before making any changes, verify that the tenant has a Sophos Mobile or Sophos Mobile Device Management license for device management and that the person carrying out the work is authorized as an administrator in Sophos Mobile for Setup > Apple setup > APNs (Sophos Fusion role Admin or Super Admin). Helpdesk or read-only access and a Mobile Threat Defense-only license are not sufficient. Confirm responsibility for the original Apple Account separately: access to the Apple Account does not replace Sophos administrator permissions. Before any renewal, first verify the existing Topic and the original Apple Account. This article covers only the APNs certificate used to manage iPhones, iPads, and Macs with Sophos Mobile; Apple Business registration and Apps and Books tokens, TLS/SCEP certificates, and the separate Mobile Threat Defense app are outside its scope. Sophos states that the certificate is valid for one year. Plan the renewal before expiry with the person responsible for the account.

Create an APNs certificate for the first time

For initial setup only: An APNs certificate must never have been uploaded to this Sophos Mobile tenant before. An existing or expired certificate belongs in the renewal and identity-resolution process below, not in Create a new APNs certificate. The license and administrator prerequisites above also apply here. Before making changes, verify the tenant, the Apple MDM assignment, and responsibility for the account, and obtain separate authorization to create the certificate; a tenant or enrollment prerequisite check does not authorize an upload. Apple Business/ADE is not a general prerequisite for an APNs certificate.

  1. Open Setup > Apple setup, select the APNs tab, and start APNs certificate wizard. On Mode, select Create a new APNs certificate.
  2. On CSR, use Download certificate signing request to save the certificate signing request as apple.csr on the local computer. You will need this file in the Apple portal.
  3. For this first-time creation, Sophos recommends a dedicated Apple Account for the company and its use with Sophos Mobile, even if another account already exists. On Apple ID, Create Apple ID in the Apple portal opens Apple’s account creation page. Store the credentials securely and make them accessible to authorized colleagues: The company needs the same account for annual renewal. This recommendation is not a reason to create a new account during renewal.
  4. In the wizard’s Apple ID field, enter the email address of the Apple Account designated for this creation. On Certificate, use Create certificate on the Apple portal to open the Apple Push Certificates Portal, sign in with that account, and upload the apple.csr you just saved.
  5. Download the generated APNs certificate file .pem from the Apple portal and save it locally. Back in the Sophos wizard, on Upload, select Upload certificate, choose that exact .pem, and select Save. Protect account credentials and certificate files.

Sophos Mobile reads the certificate and displays its details on the APNs tab. Check these details and record the Topic, expiry date, responsible Apple Account, and responsibility for renewal for the handover, without copying credentials into tickets or review logs. Saved details do not yet prove that device management works. Pilot enrollment and operational acceptance still require separate approval. If any details are unexpected, stop further steps and resolve them with the responsible Mobile administrator; removing the certificate or trying another upload is not a substantiated recovery path.

Before renewal: verify the existing identity

  1. Identify the affected Sophos Mobile tenant and record the expiry date. In Sophos Fusion > My Products > Mobile > Setup > Apple setup > APNs, note the Topic of the certificate already on file.
  2. Sign in to the Apple Push Certificates Portal with the Apple Account originally used for this certificate. For the relevant entry, read the value after UID= under Certificate Info > Subject DN: it must match the Sophos Topic. A name or email address alone is no substitute for this check. If the account’s email address has changed, establish separately whether it is still the same underlying account.
  3. No matching entry or no access to the original account? Stop. Do not renew another entry on a hunch or upload a new APNs certificate. First resolve the account-to-certificate association through the appropriate Apple and Sophos support channels for this tenant.

Renew the same certificate — do not create a new one

The renewal procedure documented by Sophos applies to a certificate nearing expiry and assumes that the identity check above has been completed:

  1. Select Setup > Apple setup > APNs > APNs certificate wizard > Renew my APNs certificate and download a new apple.csr. On the Apple ID page, compare the account shown with the original account identity established earlier; stop if a discrepancy remains unresolved.
  2. On Certificate, use Renew certificate on the Apple portal to open the Apple Push Certificates Portal and sign in with the previously verified original Apple Account. Select Renew for the matching existing certificate and upload the apple.csr you just downloaded.
  3. Download the renewed .pem from the Apple portal and save it locally. Back in the Sophos wizard, on Upload, use Upload certificate to choose that exact .pem, then select Save. Protect account credentials and certificate files.

According to Sophos, Create a new APNs certificate is for initial setup when no certificate has been uploaded yet, not a substitute for renewal.

Stop if the Topics differ: If Sophos displays a warning when saving that the new certificate’s Topic does not match the old one, cancel the dialog; do not confirm it. Resolve the mismatch first. Sophos explicitly warns that confirming it will make existing iPhones, iPads, and Macs unmanageable and require them to be re-enrolled. Removing the APNs certificate is not a fix either: according to Sophos, Apple devices still under management will become unmanaged and must be re-enrolled.

Intentionally end Apple device management: a separate offboarding process

Removal is intended only for a separately authorised permanent end to the management of iPhones, iPads and Macs, not for renewal, troubleshooting, recovery or rollback. If the certificate remains in the account, Sophos Mobile displays a persistent warning after its one-year validity expires.

Before removal: Verify the correct tenant, the licence and administrator prerequisites above, and the approved offboarding assignment. The responsible Mobile administrator must confirm from the current device inventory that no iPhones, iPads or Macs remain under management. Separately clarify and document the consequences for devices, data and the entire enrolment/management lifecycle; this is not a device or data deletion procedure. If Apple devices are still managed or the inventory is unclear, stop and do not remove the certificate. According to Sophos, any still-managed devices that are overlooked become unmanaged and must be re-enrolled.

Only after these preflight checks and explicit change approval:

  1. Open Setup > Apple setup and select the APNs tab.
  2. Select Remove APNs certificate and, only after rechecking the tenant and offboarding approval, select Yes in the confirmation dialog.

The documented result is removal of the certificate from the Sophos Mobile account; this does not imply deletion of the Apple Account or data, or an established recovery path. Afterwards, check the certificate and status display on APNs locally and document the observation. If the state is unexpected, stop further changes and resolve it with the responsible Mobile administrator; do not create or upload a certificate on a hunch. This follow-up check is required but was not performed in a tenant or on devices for this article.

Expiry and follow-up checks: no guarantee of recovery

If it has already expired: Apple says clients will no longer receive MDM updates until an updated certificate is installed in the MDM system. Before uploading anything, establish whether the original portal entry can still be renewed in this particular case and whether the Topic matches. If the original account is inaccessible or the Topic differs, stop and escalate the specific tenant case. There is no substantiated general 30-day window, guaranteed recovery, account transfer, or rollback after an incorrect upload. Plan re-enrollment only after a separate assessment of the consequences; do not assume it is necessary in every expiry case.

After a normal save, check the certificate details and new expiry date in the Sophos APNs view, as well as the Topic match against the original portal entry. Operational approval also requires a harmless, authorized MDM status/read operation on a pilot device with an actual response from the device; a successful upload alone does not prove that device management has been restored. Neither a tenant nor a device was tested for this article.

Check APNs connectivity on iPhone/iPad

The Sophos Mobile Control Check APNs function on iPhone/iPad measures only whether the APNs server is reachable; it does not verify the certificate identity or test a Mac. The device navigation is separate from the administrative certificate wizard:

  1. On the iPhone/iPad, tap Corporate management in the Sophos Mobile Control app.
  2. On the Management info page, tap Check APNs. The app attempts to reach the Apple APNs server; the expected response time is no more than five seconds.

APNs server unreachable? Work with the person responsible for the network to check the firewall settings for the device’s actual network path. For APNs, Sophos specifies the Apple destination 17.0.0.0/8 and port 5223. Separately, device management requires HTTPS 443 to the regional Mobile device endpoint. In the affected account, open My Products > Mobile and determine the actual Sophos Fusion region from the first component of the browser hostname immediately after smc-user-if-cloudstation-; do not use the company’s location or the language as the region. The complete regional device FQDNs and their mappings are in the Mobile connection paths guide, under “Device to Sophos Mobile (outbound)”. Use only the device egress destination for the identified region there: the administrative smc-user-if-cloudstation- host is not a device destination, and the separate SCEP inbound connections are not APNs or Mobile device permissions.

Do not change firewall rules on a hunch or bypass certificate validation. After a separately approved network correction, run Check APNs again; even a successful response replaces neither the Topic check nor the authorized MDM check on a pilot device described above. It provides no guarantee of recovery.