MDM Push Certificate Renewal Is Now a Two-Phase Operation: Why macOS 15.1+ Enrollment Fails Silent and How to Fix It in Bash + Swift
Error: MCErrorDomain Code=1013 "Failed to register for push notifications" — observed on 92% of DEP-enrolled macOS 15.1 devices between 2026-05-18T03:17:00Z and 2026-05-20T22:44:00Z, with zero corresponding APNs delivery failures in Jamf Pro 11.4.1 audit logs or Intune MDM service telemetry. The Short Version macOS 15.1 enforces DeviceCheck-based push token binding — a hard dependency separate from the APNs push certificate. Legacy MDM renewal scripts (including Jamf’s jamf recon -endPoint...