Apple Business User Guide
- Welcome
-
-
-
- Intro to Configurations
-
- AirDrop configuration
- AirPlay configuration
- AirPrint configuration
- App Access configuration
- Apple Intelligence & Siri configuration
- Application Layer Firewall configuration
- Certificate configuration
- Content Caching configuration
- Custom configuration
- Data Management configuration
- Energy Saver configuration
- FileVault configuration
- Gatekeeper configuration
- iCloud configuration
- Lock Screen configuration
- Password and Screen Unlock configuration
- Software Update configuration
- VPN configuration
- Web Clip configuration
- Web Filter configuration
- Wi-Fi configuration
- Edit a configuration
- Apply Blueprints
-
- Glossary
- Document revision history
- Copyright and trademarks

Create a Certificate configuration in Apple Business
Certificates are a crucial part of device security. They’re used to check the validity of an organization’s website, access networks, sign and encrypt mail messages, and more. Certificates are also used when FileVault is turned on for a Mac in your organization.
iPhone, iPad, Mac, and Apple Vision Pro devices come preinstalled with certain Root certificates. Root certificates are used on the internet to verify websites (using https) and your organization may also have their own root certificate or other certificates they want all users to have. Most certificates are signed and contain a public key, information about the website, network, or user, and are signed (verified) by a Certificate Authority (CA). Apple Business supports certificates in the Privacy Enhanced Mail (.pem) format.
Important: Certificates generally expire after one year, so if you are sending certificates to devices, you need to set a reminder for 11 months after the certificates were created to remind you to either renew or replace the certificates.
See Intro to certificate management for Apple devices in Apple Platform Deployment.
In Apple Business, sign in with a user whose role has permissions to create, edit, and delete device configurations.
To view roles and permissions, see Intro to roles and permissions.
In your browser, choose Devices > Configurations > All Configurations.
Select All Configurations, select Add
next to Certificate
, then enter a name for the configuration.Choose the platforms to create the configuration for, such as:
iOS/iPadOS
macOS
visionOS
Enter a name for the root certificate, select Choose file, select your certificate, then select Upload.
Select Save.