Today I had I continue configuring the iPad for a customer now that the Apple Buainess account had been approved. Since this was the first corporate owned Apple device they had purchased and wanted managed. I needed to connect Intune to Apple Business Here is the second part to the managing apple devices in Intune.
If Intune is your MDM and you’re deploying Apple kit at scale, Apple Business and Intune need to be talking to each other before a single corporate iPhone, iPad, or Mac goes out the door.
People overthink this integration. It’s a certificate swap. Pull a public key from Intune, hand it to Apple, bring Apple’s token back home. Three steps, fifteen minutes, done.
Here’s how to set it up.
Phase 1: Grab the public key from Intune
You’re generating an encryption key in your tenant so Apple knows who it’s trusting.
- Sign in to the Microsoft Intune admin center.
- Go to Devices > Enrollment (under Device onboarding) > Apple.
- Select Enrollment program tokens and click Create.
- Tick the box agreeing to let Microsoft send user and device info to Apple.
- Click Download your public key — this grabs the .pem certificate.
- Keep this tab open. You’ll need it again in a minute.

Phase 2: Build the MDM server in Apple Business
Open a new tab and log in to Apple Business. https://business.apple.com/ You’ll need the Administrator or Device Enrollment Manager role.
At the top select Devices, click your Management Services, then Add device management service click Add.

Under Set up device management, select Connect to external device management, then click the continue button at the bottom.

Give it a sensible name — “Corporate Intune MDM” does the job.
Under MDM Server Settings, upload the .pem file from Phase 1, and click the blue Next button

Click Download Service token. and click Done.

Phase 3: Upload Apple’s token back into Intune
- Back to your Intune tab.
- In the Apple ID box, enter the corporate Apple ID tied to your ABM account. Worth a comment here for whoever inherits this tenant down the line — they’ll want to know which Apple ID this is.
- In the Apple token box, upload the .p7m file from Apple.
- Click Next to skip past scope tags (unless your org actually uses them), then Create.

What happens next
Token status flips to Active and the plumbing’s in place. Two jobs left:
Assign hardware in Apple Business. Head to Devices, find your serial numbers or order numbers, assign them to the Intune MDM server you just created.
Sync and build profiles in Intune. Back to your enrollment token settings, hit Sync to pull the newly assigned serials through. Once they show up, build your Enrollment Program Profiles — force supervision, lock the MDM profile, skip the setup assistant screens for the end user.
One thing to flag for future you: these tokens expire annually. Stick a reminder in the calendar now, or you’ll be doing this again in a panic next year.
