Hi Yogesh-Shede, please see our documentation on creating a custom role in Intune to learn more about custom roles in Intune.
Birendrakumar, an Apple MDM Push certificate is required to manage iOS/iPadOS and macOS devices in Microsoft Intune and enables devices to enroll via the Intune Company Portal app or Apple bulk enrollment methods, such as the Device Enrollment Program, Apple School Manager, and Apple Configurator. If you are not currently managing devices via MDM, then no further action is required. To learn more about obtaining an Apple MDM push certificate with Intune, please see: Get an Apple MDM Push certificate for Intune to learn more.
mattb_known, it is recommended that the certificate is to be renewed before it expires to avoid any chance of interruptions. Note that the associated Apple ID will receive an email notification from Apple's Push Notification Service with a reminder that the certificate will expire soon. You could also setup custom alerts to renew ahead of time to maintain the connection between your Intune tenant and Apple account prior to its expiration. Keep in mind that the MDM push certificate will be associated with the Apple ID you previously used to create it; renew the certificate with this same Apple ID. If the Apple MDM certificate is deleted, you will need to reset and re-enroll devices with a new certificate.
To learn more about Apple MDM push certificates (including VPP tokens or Apple Business Manager location tokens, please see our docs below):
Get an Apple MDM Push certificate for Intune
Manage Apple volume-purchased apps