Category Filter
 
 

Last updated: August 14, 2026

Certificate

This page explains the Certificate policy in Mobile Device Management (MDM), which enables administrators to deploy server CA certificates to managed iOS, macOS, and tvOS devices. The policy helps secure and validate network communications between devices and internal or external websites, supporting use cases like securing Wi-Fi, email, and S/MIME connections. It covers configuring the certificate file, handling password-protected certificates, and managing certificate renewals. For large-scale deployments, the page also points to SCEP as an alternative.

Certificate policy lets you deploy server CA certificates, to secure and configure features such as, Wi-Fi, E-mail etc., in the managed devices. This policy lets you distribute certificates to mobile devices and ideally used to secure and validate network communications from the device to any internal/external website. By pushing certificates to device, you can secure access to networks/servers, secure e-mail communication etc., For example, you can deploy CA certificates to the managed devices, if your organization uses S/MIME to connect to a network/server. The certificates pushed to the device ensures the devices trusts the enterprise CA. This payload is supported for macOS, tvOS and iOS devices.

For scaleable and and simplified distribution of certificates in large organizations, you can configure Simple Certificate Enrollment Protocol(SCEP)

Policy Description

SpecificationDescription
Certificate FileThe file to be pushed to the managed devices
PasswordThis optional parameter must be entered if the certificate is password protected
  1. The certificates are added only if the certificate files are not corrupt and the correct password is provided in case of password-protected certificates.
  2. On certificate expiry, upload the renewed certificate as a new certificate in the profile and then push it to the managed devices.

Frequently Asked Questions

  • Which Apple platforms support the Certificate profile in ManageEngine MDM? The Certificate profile in ManageEngine MDM can be deployed to managed iOS, macOS, and tvOS devices to secure network communications.
  • What is the purpose of deploying CA certificates to iOS devices via MDM? CA certificates establish device trust with the enterprise certificate authority, securing and validating network communications such as corporate Wi-Fi connections and email servers.
  • Do users need to manually trust certificates deployed through ManageEngine MDM? No, certificates deployed via MDM profiles are automatically trusted by the device, eliminating the need for users to manually install or approve enterprise certificates.
Jump To