For the complete documentation index, see llms.txt. This page is also available as Markdown.

Report Apple Mdm Cert Expiry Scheduled

Monitor/Report expiry of Apple device management certificates

This is a scheduled runbook. It is designed to run on a recurring schedule rather than being triggered for a single object. See Scheduling for details on how to configure runbook schedules.

Description

Monitors expiration dates of Apple Push certificates, VPP tokens, and DEP tokens in Microsoft Intune. Sends an email report with alerts for certificates/tokens expiring within the specified threshold.

Setup regarding email sending

Sending an email report is optional and only happens when a recipient (EmailTo) is provided. The sender address is taken from the RJReport.EmailSender tenant setting.

This runbook sends emails using the Microsoft Graph API. To send emails via Graph API, you need to configure an existing email address in the runbook customization.

See the RealmJoin Report Settings documentation for details on all available settings.

Email branding

The report email honors the optional RJReport.Branding.* tenant settings:

  • Header and footer image – public HTTPS URLs, PNG/JPEG/GIF, max. 200 KB each

  • Footer link – target of the footer image

  • Accent and text color – 6-digit hex values, e.g. #0052cc

When these settings are not configured, the default RealmJoin graphics and colors are used. An image that cannot be downloaded or validated, or an invalid color value, never prevents the report email – the corresponding default is used instead.

Setup instructions and image requirements: Email branding.

Location

Organization → General → Report Apple MDM Cert Expiry (Scheduled)

Full Runbook name

rjgit-org_general_report-apple-mdm-cert-expiry_scheduled

Details

Property
Value

Version

1.2.0

Required modules

RealmJoin.RunbookHelper (>= 0.8.9) Microsoft.Graph.Authentication (>= 2.39.0)

Schedulable

yes

Permissions

Application permissions

  • Type: Microsoft Graph

    • DeviceManagementServiceConfig.Read.All

      • Reads the APNs certificate, Apple VPP tokens and DEP onboarding settings to check expiry dates

    • DeviceManagementConfiguration.Read.All

      • Covers the tenant info read via GET /organization used in the report header

    • Mail.Send (optional — feature: Email report)

      • Sends the expiry report via Send-RjReportEmail when a certificate or token expires within the threshold

Parameters

Days

The warning threshold in days. Certificates and tokens expiring within this many days will be flagged as alerts in the report. Default is 30 days.

Property
Value

Required

false

Default Value

30

Type

Int32

Portal display name

Days Until Expiration Warning

EmailTo

Can be a single address or multiple comma-separated addresses (string). The function sends individual emails to each recipient for privacy reasons.

Property
Value

Required

false

Default Value

Type

String

Portal display name

Recipient Email Address(es)

EmailFrom

The sender email address. This needs to be configured in the runbook customization

Property
Value

Required

false

Default Value

Type

String

Hidden in portal

yes (preset via runbook customization)

BrandingHeaderImageUrl

Optional public HTTPS URL of a custom header image (PNG/JPEG/GIF, max. 200 KB) for the report email. Sourced from the RJReport.Branding.HeaderImageUrl tenant setting. When empty, the default RealmJoin header graphic is used.

Property
Value

Required

false

Default Value

Type

String

Hidden in portal

yes (preset via runbook customization)

BrandingFooterImageUrl

Optional public HTTPS URL of a custom footer image (PNG/JPEG/GIF, max. 200 KB) for the report email. Sourced from the RJReport.Branding.FooterImageUrl tenant setting. When empty, the default RealmJoin footer graphic is used.

Property
Value

Required

false

Default Value

Type

String

Hidden in portal

yes (preset via runbook customization)

Optional URL the footer image links to. Sourced from the RJReport.Branding.FooterLink tenant setting. When empty, the default link (https://www.realmjoin.com) is used.

Property
Value

Required

false

Default Value

Type

String

Hidden in portal

yes (preset via runbook customization)

BrandingAccentColor

Optional accent color override (6-digit hex, e.g. '#0052cc') for the report email template. Sourced from the RJReport.Branding.AccentColor tenant setting. When empty or invalid, the default RealmJoin accent color is used.

Property
Value

Required

false

Default Value

Type

String

Hidden in portal

yes (preset via runbook customization)

BrandingTextColor

Optional text color override (6-digit hex) for the report email template. Sourced from the RJReport.Branding.TextColor tenant setting. When empty or invalid, the default RealmJoin text color is used.

Property
Value

Required

false

Default Value

Type

String

Hidden in portal

yes (preset via runbook customization)

Last updated

Was this helpful?