MDM Solution Comparison
Evaluated across the seven-pillar Amaris framework, plus an AI & Intelligence pillar we added. 8 vendors, checked against 2026 list pricing.
Already down to two? Every pair is priced and scored head to head.
Pillar 1: Apple Integration Depth
Granular Apple deployment, new feature adoption, and ecosystem integration depth
- Granular Apple deployment and new specific features
- New features cycle and beta testing
- Innovation and extended features
- Integration with Apple's GitHub (device management)
- Support for Apple services (Managed Apple Accounts)
- Enrolment methods
| Feature | Apple BusinessFree Apple built-in | Jamf ProTop Apple score Apple Enterprise | Iru Modern UEM | Intune Microsoft UEM | MosyleLow Cost Apple-focused | Workspace ONE Omnissa UEM | Addigy MSP / SMB | Fleet Open Source |
|---|---|---|---|---|---|---|---|---|
Monthly feature & settings updatesFrequency of new MDM feature releases and Apple setting supportIntune: quarterly plan, not all Apple settings implemented | ||||||||
DDM (Declarative Device Management)Support for Apple's modern declarative management protocol | ||||||||
Beta program for new featuresPre-release testing of new MDM capabilities | ||||||||
Apple GitHub device management integrationBlueprints integrated with Apple's device management repo | ||||||||
Return to ServiceRemote wipe and re-enrollment without physical accessIntune: to be implemented | ||||||||
Managed Apple Accounts supportSupport for Apple services including Managed Apple Accounts | ||||||||
Enrollment methods (ADE + ADUE)Automated Device Enrollment and Account-Driven User Enrollment | ||||||||
Day-0 macOS supportSame-day support for new Apple OS releases |
Pillar 2: Identity Management
IdP integration, Platform SSO, authentication methods, and admin security
- Integration with the main IdPs
- Platform SSO ready
- Authentication methods during enrolment
- Authentication for administrators
| Feature | Apple BusinessFree Apple built-in | Jamf ProTop Apple score Apple Enterprise | Iru Modern UEM | Intune Microsoft UEM | MosyleLow Cost Apple-focused | Workspace ONE Omnissa UEM | Addigy MSP / SMB | Fleet Open Source |
|---|---|---|---|---|---|---|---|---|
IdP integration (Okta, Entra, Google)Integration with major identity providers and directory services | ||||||||
Platform SSO readinessSupport for Apple Platform SSO during and after enrollmentIntune: not available during Setup Assistant. Jamf: Okta supported during setup | ||||||||
Modern auth during enrollmentAuthentication methods available during device enrollment | ||||||||
Passkey authenticationSupport for passkeys as modern authentication method | ||||||||
Admin authentication & MFASecure authentication methods for management console access |
Pillar 3: Advanced Features
API automation, web filtering, IaC, and role-based access control
- API and automation
- Web filtering
- Security software tailored for Apple deployments
- Infrastructure as code
- Role-based access
- AI configurations and guidance
| Feature | Apple BusinessFree Apple built-in | Jamf ProTop Apple score Apple Enterprise | Iru Modern UEM | Intune Microsoft UEM | MosyleLow Cost Apple-focused | Workspace ONE Omnissa UEM | Addigy MSP / SMB | Fleet Open Source |
|---|---|---|---|---|---|---|---|---|
API & automationProgrammatic access to MDM features for automationIntune: API partially implemented for Apple features. Jamf: two API implementations | ||||||||
Web / content filteringBuilt-in or integrated content filtering capabilitiesJamf: Jamf Trust. Intune: via Defender & config profiles | ||||||||
Apple-tailored security softwareSecurity tools specifically designed for Apple deployments | ||||||||
Infrastructure as CodeManage MDM configurations through code and version controlJamf: possible with third-party tools. Intune: no IaC implementation | ||||||||
Granular role-based accessFine-grained administrator permissions and access controlIntune/WS1: strong granular RBAC. Jamf: limited and complex |
Pillar 4: Security & Compliance
Built-in benchmarks, conditional access, Zero Trust, and compliance enforcement
- Built-in benchmark implementation
- Faster check-in
- Faster policy reference in specialised tools
- Conditional access integration
- BeyondCorp (Zero Trust)
| Feature | Apple BusinessFree Apple built-in | Jamf ProTop Apple score Apple Enterprise | Iru Modern UEM | Intune Microsoft UEM | MosyleLow Cost Apple-focused | Workspace ONE Omnissa UEM | Addigy MSP / SMB | Fleet Open Source |
|---|---|---|---|---|---|---|---|---|
Built-in compliance benchmarksNative CIS/NIST/DISA STIG benchmark implementationJamf: mature Compliance Editor with CIS/NIST/DISA STIG. Intune: requires scripts & profiles via macOS Security Compliance Project | ||||||||
Automated remediationSelf-healing compliance with automated enforcement and remediationIntune: remediation dependent on scripts and sync cycle | ||||||||
Conditional access integrationDevice compliance-based resource access controlsJamf: MS + Google BeyondCorp. WS1: MS + Google BeyondCorp. Intune: native MS conditional access | ||||||||
Zero Trust (BeyondCorp)Google BeyondCorp integration for Zero Trust access | ||||||||
Security benchmark dashboardsVisual compliance status and security posture reportingIntune: security benchmark dashboards not available for Apple | ||||||||
FileVault escrow & recoverySecure storage and retrieval of macOS encryption keys | ||||||||
Endpoint Detection & ResponseBuilt-in or deeply integrated macOS threat detectionJamf Protect native; Intune requires Defender add-on; Mosyle built-in malware scanning |
Pillar 5: Visibility & Remediation
Device scoping, smart groups, custom dashboards, and SIEM integration
- Device scoping
- Target groups and deployment
- Dashboard and custom visibility
- Integration with SIEM
| Feature | Apple BusinessFree Apple built-in | Jamf ProTop Apple score Apple Enterprise | Iru Modern UEM | Intune Microsoft UEM | MosyleLow Cost Apple-focused | Workspace ONE Omnissa UEM | Addigy MSP / SMB | Fleet Open Source |
|---|---|---|---|---|---|---|---|---|
Smart groups & device scopingGranular device targeting with dynamic group assignmentJamf/WS1: robust smart groups. Intune: device filtering limited to 9 properties | ||||||||
EntraID/Google group assignmentUse identity provider groups for configuration assignment | ||||||||
Custom dashboards & visibilityCustomizable dashboards for device status and complianceIntune: 10 built-in categories + Azure Resource Graph. WS1: advanced with Omnissa Intelligence | ||||||||
SIEM / EDR integrationIntegration with security information and event management toolsJamf: webhooks + API. Intune: native MS Defender/Sentinel. WS1: built-in SIEM integration | ||||||||
Device compliance detail reportingDetailed device record with installation status and complianceWS1: extensive details including app & profile installation status | ||||||||
Hardware & software inventoryComprehensive reporting on device hardware and installed software |
Pillar 6: Apps & OS Software Updates
App catalog, patch management, DDM updates, and Self Service portals
- App catalog
- Patch management in Apple-centric tools
- Apple installation methods support
- DDM for software update implementation
- Self Service
| Feature | Apple BusinessFree Apple built-in | Jamf ProTop Apple score Apple Enterprise | Iru Modern UEM | Intune Microsoft UEM | MosyleLow Cost Apple-focused | Workspace ONE Omnissa UEM | Addigy MSP / SMB | Fleet Open Source |
|---|---|---|---|---|---|---|---|---|
Built-in app catalog & patchingNative patch management with large app catalogJamf: 1,400+ patch titles, automatic updates. Intune: good PKG/App Store support, lacking robust 3rd-party patching | ||||||||
macOS patch titles (native)Number of natively supported app patch titles | None | 1,400+ | ~1,000 | ~400 | ~800 | ~350 | ~900 | ~200 |
Apple installation methods supportSupport for PKG, DMG, App Store, and custom installers | ||||||||
DDM software update managementDeclarative Device Management for OS update enforcementJamf/Intune/WS1: DDM fully implemented with status reporting | ||||||||
Self Service portalUser-facing app catalog with installation and remediationJamf: Self Service+ with compliance, admin elevation, branding. Intune: Company Portal, less flexibility. WS1: Intelligent Hub with branding | ||||||||
App Store VPP managementVolume purchasing and silent app deployment |
Pillar 7: Ease of Use Maturity
Learning curve, training, community resources, and admin experience
- Learning curve
- Training and certification
- Resources required to implement and maintain device management
| Feature | Apple BusinessFree Apple built-in | Jamf ProTop Apple score Apple Enterprise | Iru Modern UEM | Intune Microsoft UEM | MosyleLow Cost Apple-focused | Workspace ONE Omnissa UEM | Addigy MSP / SMB | Fleet Open Source |
|---|---|---|---|---|---|---|---|---|
Learning curveTime and effort required for administrators to become proficientJamf: Apple-centered, mature product. Intune: Apple workflows require more work. WS1: UI lacks intuitiveness | ||||||||
Training & certification programsVendor-provided training courses and professional certificationsJamf: largest learning hub & community. MS: Endpoint Administrator Associate cert. WS1: multiple cert levels | ||||||||
Resources to implement & maintainStaffing and expertise requirements for deploymentSpecialized Mac admins recommended for Jamf, Intune, and WS1 in complex environments | ||||||||
Community & documentationQuality of documentation, community forums, and knowledge baseJamf: Jamf Nation is the largest Apple admin community. Fleet: strong open-source community | ||||||||
Intuitive admin experienceOverall UI/UX quality of the management consoleIru: frequently praised for intuitive UI. WS1: UI lacks intuitiveness per reviews |
Pillar 8: AI & Intelligence
Admin-side AI assistants, predictive analytics, and governance of AI on managed devices. Entitlements checked against vendor documentation, 2026. Hover rows for the licensing detail.
| Feature | Apple BusinessFree Apple built-in | Jamf ProTop Apple score Apple Enterprise | Iru Modern UEM | Intune Microsoft UEM | MosyleLow Cost Apple-focused | Workspace ONE Omnissa UEM | Addigy MSP / SMB | Fleet Open Source |
|---|---|---|---|---|---|---|---|---|
Natural-language device searchQuery fleet inventory and device state in plain EnglishJamf: AI Assistant Search skill (cloud-hosted Jamf Pro only). Iru: Kai, enabled by default for all customers. Omnissa: Omni assistant, GA March 2026. Intune: Copilot device query | ||||||||
AI configuration & policy guidanceAI-assisted setup, policy recommendations, and misconfiguration detectionJamf: AI Assistant explains policies, scripts, Smart Groups and blueprints. Intune: Copilot policy insights & error explanations. Fleet: optional AI-generated policy descriptions and remediations (4.50.0+) | ||||||||
AI security explainabilityPlain-English explanation of compliance drift and risky settingsJamf: shipped scope covers configuration and compliance benchmarking; Jamf Protect alert analysis is announced as coming soon. Intune: Security Copilot integration. Omnissa: Intelligence anomaly context | ||||||||
AI scripting assistantGenerate, audit, and explain management scripts with AIMosyle AIScript: natural-language macOS script generation, included for Fuse/OneK12. Addigy: AI Script Assistant in the script editor (documented as a time-limited premium preview). Jamf: published AI tools are read-only, explaining scripts rather than generating them. Intune: Copilot for PowerShell, weaker for shell/macOS | ||||||||
Predictive analytics & anomaly detectionML-driven fleet health, experience scoring, and outlier detectionOmnissa: Intelligence + DEX scoring is class-leading, though Experience Management is a licensed add-on. Intune: Advanced Analytics moves into M365 E3/E5 base plans from July 2026, or $5/user/mo standalone | ||||||||
Apple Intelligence managementGranular MDM control of Apple Intelligence, Genmoji, and Writing Tools on devicesAddigy shipped controls Aug 2024, ahead of the public macOS 15 / iOS 18 release. Intune added Settings Catalog keys in March 2025 and DDM configurations in March 2026 after Apple deprecated part of the restrictions payload in iOS/macOS 26.4 | ||||||||
GenAI usage governanceVisibility and control over AI coding tools and shadow AI on managed devicesJamf AI Governance GA 30 June 2026, included in the Jamf for Mac plan; day-one coverage is Claude Code, Claude Desktop and OpenAI Codex. Intune: via Defender + Purview licensing | ||||||||
AI pricing modelHow vendor AI capability is licensed*Jamf AI Assistant requires cloud-hosted Jamf Pro (not on-premises or GovCloud); AI Governance sits in the Jamf for Mac plan, not Jamf Pro base. †Security Copilot, which powers Copilot in Intune, is included for M365 E5/E7 (400 SCUs per 1,000 licenses); customers without E5/E7 provision SCUs separately. No Intune Suite licence is required for Copilot in Intune. Omnissa: Experience Management (DEX) is a licensed add-on; Omni entitlement is not published | None | Included* | Included | Included (E5/E7)† | Included | Add-on | Preview | Free/BYO |
Cost Structure & TCO
All prices checked against vendor list pricing in 2026. Hover rows for the source and date.
| Feature | Apple BusinessFree Apple built-in | Jamf ProTop Apple score Apple Enterprise | Iru Modern UEM | Intune Microsoft UEM | MosyleLow Cost Apple-focused | Workspace ONE Omnissa UEM | Addigy MSP / SMB | Fleet Open Source |
|---|---|---|---|---|---|---|---|---|
Base license (per device/mo)Vendor list pricing, re-verified August 2026 -- standard enterprise tier*Standalone Plan 1. $2/user/mo if attributed from E3; $4/user/mo from E5 (Forrester TEI). Microsoft raised M365 E3 to $39 and E5 to $60 on 1 July 2026, bundling Intune Plan 2 into both. Apple Business is free; Apple publishes no device-count limit, though consultancies report gaps starting around 30-50 devices | Free | $7.89 | $6.00 | $8.00* | $1.00 | $9.00 | $8.25 | Free/Custom |
Full security bundleMDM + EDR + identity protection includedJamf for Mac bundle; Intune Suite; list prices re-verified August 2026 | N/A | $12.50 | $8.00 | $18.00 | $3.50 | $15.00 | $14.00 | N/A |
Implementation timelineTypical enterprise deployment duration | Days | 6-10 wk | 4-8 wk | 8-12 mo | 2-4 wk | 6-12 mo | 2-6 wk | 4-8 wk |
FTE per 1,000 devicesDedicated IT staff required for ongoing management | <0.1 | 0.2-0.3 | 0.2-0.4 | 0.5-1.0 | 0.1-0.2 | 0.4-0.8 | 0.3-0.5 | 0.3-0.5 |
Policy delivery latencyTime from policy change to device enforcement | Not published | Seconds | Seconds | 8-24 hrs | Seconds | 1-4 hrs | Minutes | 1-2 hrs |
3-Year TCO / 1,000 endpointsTotal cost of ownership benchmark (all-in) | Not applicable | ~$303,000 | ~$260,000 | ~$436,000 | ~$106,000 | ~$808,000 | ~$280,000 | ~$274,000 |
Start from free: Apple's built-in device management
New, April 2026Apple Business merged Apple Business Manager, Business Essentials and Business Connect into one free console, and the per-device fee went with it. For a small Apple fleet that is a real answer, so treat it as the baseline every paid platform below has to out-earn.
Show the detailHide the detail
Start from free: Apple's built-in device management
New, April 2026Apple Business merged Apple Business Manager, Business Essentials and Business Connect into one free console, and the per-device fee went with it. For a small Apple fleet that is a real answer, so treat it as the baseline every paid platform below has to out-earn.
Show the detailHide the detailWhat it covers
- Automated Device Enrolment: zero-touch, fully supervised setup for new or erased devices
- Account-driven enrolment for BYOD and in-use devices: no wipe, work data separated via a Managed Apple Account
- Blueprints: preconfigured settings and apps applied at first boot, and reapplied automatically on device replacement
- Managed Apple Accounts, federated with Entra ID or Google Workspace
- App and Book (VPP) distribution through Blueprints
- Core restrictions and DDM-based configuration profiles
- Activation Lock, remote lock and wipe, on supervised (ADE) devices only
- External Management: link a paid MDM (Jamf, Mosyle, etc.) alongside Apple Business. Device assignment stays here, day-2 management moves to the paid platform
Where it stops
- No managed app configuration (AppConfig), so users configure each app by hand
- No email account payloads (Exchange, Gmail, IMAP)
- No third-party patch management or app catalogue
- No scripting, custom reporting or public management API
- No CIS/NIST benchmark tooling or automated remediation
- Locate, lock and erase need supervised (ADE) enrolment, which BYOD accounts do not get
Apple publishes no device-count limit for this service. IT consultancies that support Apple fleets (Dr Logic, Iru) independently report real gaps starting to bite somewhere around 30 to 50 devices: app configuration, third-party patching, compliance reporting. That is their field estimate, not an Apple-stated ceiling.
Free isn't zero-effort: where Amaris fits
- Business verification: DUNS number, or since April 2026 a Federal EIN plus one supporting document. Apple's review runs about 5 business days
- Managed Apple Account rollout and identity federation (Entra ID / Google Workspace)
- Blueprints: building the app + configuration bundles new devices boot into
- If a paid MDM stays in the picture: External Management certificate upload (250-cert limit) and the annual token renewal Apple doesn't proactively warn about
Amaris scopes and runs this setup as a fixed-fee engagement, verification through to a working Blueprint, then hands off a baseline the client owns. For fleets that will outgrow the free tier, a paid MDM is layered in through External Management from day one.
Sources: Apple Newsroom, "Introducing Apple Business" (24 Mar 2026) · Apple Support, "Intro to Apple Business", "Enrollment methods for built-in device management", "Manage the built-in device management service", "Link to an external device management service" (all 14 Apr 2026) · Der Flounder, "DUNS number no longer required" (15 Apr 2026) · Dr Logic, "Apple Business Now Includes Free MDM" (28 Apr 2026). Capabilities not documented by Apple are scored as absent in the matrix below.
Switching MDM vendors got faster in iOS 26 and macOS 26
Moving a fleet between MDMs has always meant wiping every device. Apple shipped a no-wipe path in the iOS 26, iPadOS 26 and macOS 26 generation, so a migration that used to be a multi-week re-enrollment project can be a scheduled cutover instead.
Show the detailHide the detail
Switching MDM vendors got faster in iOS 26 and macOS 26
Moving a fleet between MDMs has always meant wiping every device. Apple shipped a no-wipe path in the iOS 26, iPadOS 26 and macOS 26 generation, so a migration that used to be a multi-week re-enrollment project can be a scheduled cutover instead.
Show the detailHide the detail- 1
Admin starts the migration
In Apple Business (or classic ABM), the admin reassigns already-enrolled devices to the new MDM server and optionally sets a completion deadline of between 1 and 90 days, editable and cancellable.
- 2
New MDM stages configuration ahead of cutover
Policies and profiles do not carry over automatically. The admin recreates them in the new MDM before cutover. Apps survive the switch only if the new MDM delivers them before the device checks in.
- 3
Device gets a single prompt, not a wipe
iPhone / iPad: a restart. Mac: a non-dismissible full-screen prompt. No factory reset, no user re-enrollment step, no "erase all content". The device stays supervised throughout.
- 4
Device checks in to the new MDM
Offline devices get prompted the next time they come online; escalating reminders (24-hour, then hourly) fire as the deadline approaches.
Requirements
- Devices on iOS 26, iPadOS 26 or macOS 26 or later
- Organization-owned, enrolled via Automated Device Enrollment (ADE)
- macOS 26+ also supports unenrolling from ADE and re-enrolling profile-based
Where it doesn't apply
- Doesn't apply to Apple Business's own built-in MDM: this path is vendor-to-vendor only, not a way in or out of the free tier
- Shared iPad is unsupported
- Apple Configurator-enrolled devices must clear a 30-day provisional period first
- Policies, profiles and compliance state are not carried over, only enrollment and optionally apps
Amaris plans and runs MDM-to-MDM migrations on this path where a fleet is eligible: policies rebuilt in the new MDM ahead of time, a scoped cutover window, no fleet-wide wipe.
Sources: Apple Support, "Migrate devices to a new management service in Apple Business" (14 Apr 2026) · Apple Support, "Migrate managed devices to another device management service" (28 Jan 2026) · SimpleMDM, "Apple streamlines MDM migrations in iOS 26 and macOS 26" (3 Jul 2025, WWDC25) · Miradore migration guide (7 May 2026).
Decision Factors
Key considerations when selecting an MDM solution
Apple-Centric Organizations
Heavily Apple-centric organizations are likely to benefit from a specialist MDM. These solutions provide access to cutting-edge Apple features earlier, offer more detailed control, and deliver faster updates for new OS releases.
Existing Microsoft Infrastructure
Organizations with EntraID, Microsoft 365, or Intune already in place can gain efficiencies from reusing identity, license, and compliance tools. Intune may be sufficient for many Apple management needs if some compromises are acceptable.
SMB & Cost-Conscious Teams
For smaller to medium teams where ease of setup, lower admin overhead, and cost predictability are important, lightweight Apple-focused tools provide a better return on investment.
Security Benchmark Leaders
Iru (Kandji) and Jamf are leaders in built-in, turnkey CIS/benchmark workflows with pre-built control libraries and automated remediation. Jamf provides a mature Compliance Editor with CIS/NIST/DISA STIG mappings at scale.
AI-Forward IT Teams
Compare entitlement, not marketing. Copilot in Intune needs no Intune Suite licence and is included for Microsoft 365 E5/E7, but organisations below E5 provision Security Compute Units separately. Jamf's AI Assistant requires cloud-hosted Jamf Pro, and its AI Governance module sits in the Jamf for Mac plan. Iru and Mosyle include their assistants outright. Ask each vendor which plan the AI actually ships in.
MDM Selection Guide
Key questions to evaluate MDM solutions for your organization
- 1How deeply does the MDM integrate with Apple's latest management frameworks and APIs?
- 2How important is security compliance and audit readiness for our organization?
- 3How much control and visibility do administrators require?
- 4Which activities consume the most time for your administrators and support team?
- 5What is our desired balance between cost, complexity, and support quality?
- 1Is your deployment model one-to-one, shared (non-personalized) or a combination?
- 2Is bring-your-own-device (BYOD) deployment an option for your users?
- 3Do you need to manage devices locally, nationally or internationally?
- 4What type of applications do you plan to deploy: App Store apps, custom apps, third-party apps or a combination?
- 5Do you want to offer a custom catalog for users to deploy content such as apps and documents?
- 6Do you plan to use a vendor's API to build internal tools, scripts or automations?
- 7Do you require separate, role-based access to a management console?
- 8For education: do you need Apple School Manager rosters and education profiles for student and teacher tools?
- 1Do you require management of a mixed device environment?
- 2Does the vendor provide robust support for macOS, in addition to the MDM framework?
- 3How many devices do you currently manage, and what is your projected device growth?
- 4Does the MDM solution support management of other platforms?
- 1Do you need to integrate your current directory service with the MDM solution?
- 2Do you need to integrate certificates and identities with the MDM solution?
- 3Do you plan to provide a single sign-on (SSO) option to users and administrators?
- 4Is your current identity provider supported by the MDM solution?
- 5Is your current certificate distribution mechanism supported by the MDM solution?
- 6Is your user authentication system available only on-premises?
- 7How many users does your organization have?
- 1Do you require an on-premises or self-hosted solution?
- 2Do you need to comply with geographical data and privacy regulations?
- 3Do you have devices that must remain offline?
- 4Do you require support for endpoint security management solutions?
- 5Do you need integration with internal networks that utilize proxies or VPNs?
- 6Do you need to mandate app and software updates for the latest security patches?
- 7Do you need to block specific processes and applications?
- 1Do your admins want natural-language search and AI-assisted configuration, or is the console workflow enough?
- 2Which plan does the AI actually ship in: base licence, a higher tier, or a separate entitlement (Security Compute Units below M365 E5, Jamf for Mac for AI Governance, Omnissa Experience Management)?
- 3Where is admin and device data processed when AI features are enabled, and does that satisfy your data-residency and privacy requirements?
- 4Do you need to manage Apple Intelligence, Genmoji, and Writing Tools availability on employee devices, and how fast does the vendor ship new Apple AI restriction keys?
- 5Do you need visibility into or control over ChatGPT and other GenAI tools used on managed devices (shadow AI)?
- 6Can AI-generated scripts and policies be reviewed and approved before they touch production devices?