Change/renew APNS

We are wondering, if we change te account used to configure APNS in SOTI will the current enrolled devices keep on working?

I know the manual mention the re-enrollment of devices after changing.
But does the change mean the devices need to be enrolled directly after changing or do we have time to do this on een controlled scheduled base without devices loosing funtionallity (except then voor the APNS)

3 years ago
SOTI MobiControl
ANSWERS
R
RVS17
3 years ago

Hi KAS001,

Thank you for posting this query!!.

Answering to your query, Well Generating an APNS certificate changing the current apple account associated will force all apple devices to re-enroll. 

And Yes, Change means devices need to be re-enrolled manually, after changing the account. Unfortunately, there is no such scheduled base you looking for. 

May I know further, what reasons for changing the apple account ?

R
RVS17
3 years ago

Hi KAS001,

Thank you for your post..

Has mine and Raymond's reply has solutioned your inquiry? If it's solutioned, please kindly mark solutioned. 

If not further, post your concerns regarding the inquiry.

Thanks

K
KAS001
3 years ago

Thx for the feedback.

So the devices wil NOT continue to work as they are forced un-enrolled.

I was already aware that they would need to be re-enrolled, but was hoping they would continue working.

This because for the moment, we enroll them but use them in a VLAN that doesn'tt have SOTI connection. So the devices wouldn't be aware of the changed certificate.

K
KAS001
3 years ago

And we want to change it because of a historical error

RC
Raymond Chan Diamond Contributor
3 years ago

From the moment the APNS certificate of a MobiControl server is replaced,  all previously enrolled Apple devices will get out of control by the server.  Depending the nature of each policy already deployed to such devices, some (e.g. restrictions/feature control, may continue to work to provide the original intended protection.  However, no more device check-in, device action or policy change is possible.

To regain control, each device need to be re-enrolled.   For unsupervised devices, re-enrolling just mean revoking and reinstalling trust and MDM profiles, without any need to factory reset the device.  On the contrary, re-enrollment of supervised device imply that the device has to be factory reset.  Unless you have perfect client-server implemtation for all apps on the device, or have regular full device sync/back-up to iCloud,  there is bound to be loss of user data associated with apps after the re-enrollment and subsequent re-deployment of app binary.

If your so-called need to change of APNS due to historial reason is related to unknown AppleID account or forgotten password assoicated with the previous administrator account to access the APNS portal, then it might worth the effort to contact Apple enterprise support team to see if they can do anything to help.  If your organization has account set up to access Apple Business Manager for DEP/VPP related services, then Apple is more likely able to help once they have received official request and documentation from your organization IT top management.  This is what I heard from a guy in Apple-Enterprise team in Hong Kong.

Similar Discussions