Jamf vs Intune vs Kandji: 200M vs 33M Devices [2026]

Anyone searching “Jamf vs Intune vs Kandji” in September 2026 is about to hit a wall of stale results. Kandji does not exist as a brand anymore. The company renamed itself Iru on October 22, 2025, and folded in Windows and Android management alongside its original Apple-only focus. Jamf, meanwhile, is no longer a public company: private equity firm Francisco Partners closed a $2.2 billion all-cash acquisition on January 30, 2026, taking the endpoint management vendor off the stock market entirely. Only Microsoft Intune has stayed put, riding the scale of the Microsoft 365 installed base to a reported 200 million-plus managed devices. This comparison walks through what each platform actually does today, what it costs, and which one fits a given fleet, using the current names and the current ownership structure.

Google · Preferred Sources

Don't miss new tech stories on Google

Add Tech Insider once in the Google app and our stories appear in your news suggestions.

Add Now

The Jamf vs Intune vs Kandji Question Just Got More Complicated

IT buyers researching mobile device management (MDM) tools in 2026 are running into two pieces of news that reshuffle the standard comparison. First, Kandji’s rebrand: the company’s own newsroom announcement states “Kandji is now Iru, the AI-powered IT & security platform used by the world’s fastest-growing companies to secure their users, apps, and devices,” dated October 22, 2025 and confirmed on Iru’s official site. Existing Kandji customers were not forced onto a new contract, but their consoles, branding, and product scope have shifted, and new sign-ups now land on the broader Iru platform rather than the old Apple-only Kandji product.

Second, Jamf’s ownership changed. An SEC filing exhibit tied to the deal quotes the company’s announcement that the acquisition by Francisco Partners closed “for $13.05 per share in cash, representing a total enterprise value of approximately $2.2 billion,” effective January 30, 2026, a figure independently reported by SecurityWeek and other trade outlets. Jamf’s product roadmap has not visibly slowed since the deal closed, but its quarterly earnings calls, investor disclosures, and public roadmap commentary have gone away along with its public listing. For IT teams that used Jamf’s SEC filings to gauge financial stability before signing multi-year contracts, that transparency is gone.

Neither change alters what the software does on a given Tuesday morning. But both change how buyers should evaluate long-term vendor risk, product roadmap direction, and whether “Kandji” results found through a search engine even describe the product being sold today. This article uses Iru as the current name throughout, while still referencing Kandji where that is the name attached to a specific sourced fact or historical detail.

What Mobile Device Management Actually Does for a Fleet

Mobile device management software gives IT teams a single console to enroll, configure, secure, and retire company-owned or BYOD hardware, without a technician physically touching every laptop or phone. A properly configured MDM platform pushes Wi-Fi and VPN profiles, enforces disk encryption and passcode policies, installs and updates required apps, wipes lost or stolen devices remotely, and reports on which machines are out of compliance with patch levels or security baselines. For Apple hardware specifically, that means tapping into Apple Business Manager (ABM) and Apple School Manager (ASM) for zero-touch enrollment, where a device ships from Apple, gets turned on by an end user, and automatically pulls down its full configuration before the person ever sees a home screen.

The category has broadened considerably since “MDM” first described basic device wipe-and-lock tools. Modern platforms increasingly bundle identity and conditional access, endpoint detection, vulnerability scanning, and patch orchestration under one roof, a trend Gartner now tracks under the broader “Endpoint Management Tools” label rather than plain MDM. Jamf’s own announcement of its 2026 Gartner Magic Quadrant positioning reflects that shift, framing the company as an endpoint management vendor rather than a narrower Apple-MDM specialist. This is the exact terrain where Jamf, Intune, and Iru now compete: not just who enrolls a MacBook fastest, but who can also verify patch compliance, gate access to corporate apps based on device health, and hand off alerts to a security team.

Buying the wrong tool here is expensive to unwind. Migrating a fleet of a few hundred devices between MDM platforms typically means re-enrolling every machine, re-issuing Apple Business Manager tokens, rebuilding configuration profiles from scratch, and running a support-heavy transition window where end users get prompted to re-authenticate. That switching cost is one reason MDM contracts tend to run three-plus years, and why getting the initial choice right (or understanding exactly what changed when a vendor renames itself mid-contract) matters more than it would for a lighter-weight SaaS tool.

Jamf Pro Profile: Apple-First MDM After the $2.2 Billion Buyout

Jamf built its reputation as the deepest Apple-specific management platform on the market, and that focus has not changed under Francisco Partners’ ownership. Jamf Pro’s current release line, 11.32.x, had its system requirements page updated on September 14, 2026 to list macOS 27.x, iOS 27.x, iPadOS 27.x, tvOS 27.x, visionOS 27.x, and watchOS 27.x as recommended compatibility, according to Jamf’s own release notes. That is a wider span of Apple’s ecosystem than either Intune or Iru advertises support for, including visionOS for Vision Pro headsets and tvOS for Apple TV fleets, both niche but real line items for enterprises running Apple hardware at scale.

Jamf’s 2026 release cadence has stayed active through the ownership change. Jamf Pro 11.29.1 shipped June 25, 2026, followed by the 11.29.2 maintenance release on July 2, 2026. Jamf Pro 11.30.0 landed July 14, 2026 with a new “Last Contact” inventory attribute for computers and mobile devices, giving admins a faster way to spot devices that have stopped checking in, plus updated Microsoft Entra ID connection permissions for tighter conditional-access integration. On July 20, 2026, Jamf shipped Self Service+ for mobile, a rebuilt version of its end-user app store that adds network security monitoring and centralized threat alerts when tied to Jamf Security Cloud, though devices still running iOS or iPadOS 16.x or earlier stay on the legacy Self Service 11.4.2 client.

What the Francisco Partners Deal Changes for Buyers

Going private removes Jamf from quarterly earnings scrutiny, which cuts both ways. Private equity ownership often accelerates product investment in the near term to protect the buyer’s return, and Jamf’s release cadence through mid-2026 backs that up. But it also means IT procurement teams lose the public 10-K and investor-call visibility they previously used to sanity-check Jamf’s financial health and customer retention numbers before signing multi-year renewals. Jamf was named a Leader in the 2026 Gartner Magic Quadrant for Endpoint Management Tools, a report Gartner says evaluated 16 vendors in its inaugural version of that specific report title, giving buyers at least one independent analyst signal to lean on in place of public filings.

Microsoft Intune Profile: Scale Through the Microsoft 365 Installed Base

Intune’s competitive edge has never been Apple-specific depth; it is reach. Because Intune ships as part of Microsoft 365 E3 and E5 licensing rather than as a pure standalone product, it lands on the desks of IT teams who are already Microsoft shops by default, not by a separate purchase decision. Third-party market-intelligence reporting in 2026 pegs Intune at more than 200 million managed devices, with figures citing roughly 37,119 enterprise customers, though Microsoft does not break those numbers out the way a standalone MDM vendor would in a sales deck. That scale is a direct byproduct of Microsoft 365 adoption rather than Intune winning head-to-head MDM bake-offs on its own.

Intune’s September 2026 release cadence, tracked in Microsoft’s official “What’s new in Intune” documentation, shows a platform investing heavily in Windows-side automation. The service release 2608 update, shipped the week of August 25, 2026, added unattended Remote Help sessions on physical Windows devices, letting authorized helpdesk agents sign in and control a machine without the end user present or needing to approve anything in real time. The same release listed ChatGPT as a protected app under Intune’s mobile application management (MAM) policies, meaning IT teams can now govern how corporate data flows into and out of that specific AI tool the same way they would any other managed application.

An “in development” entry for service release 2609, dated September 1, 2026, previews Advanced Analytics that extend Kusto Query Language (KQL) queries to Windows app inventory across an entire fleet, letting admins hunt for outdated or unauthorized software without touching devices one at a time. The same preview describes new Windows Autopatch controls that let admins approve, auto-approve, reject, or schedule quality updates by update type, plus Apple-side additions including support for Apple’s Enforce Routes VPN feature on iOS, iPadOS, and macOS. That last item matters for the comparison: Intune is still actively adding Apple-specific capability, even though its core identity is a Windows-first, Microsoft-365-bundled product.

Kandji Is Now Iru: Inside the October 2025 Rebrand

Kandji spent years building a reputation as the newer, cleaner-UI alternative to Jamf for Apple-only shops, particularly fast-growing startups that wanted zero-touch macOS deployment without Jamf’s enterprise complexity. That positioning changed in October 2025. Iru’s own product page states plainly: “Kandji is now Iru Endpoint… We rebranded as Iru to match the expanded scope of our product and vision,” according to the company’s newsroom. The rebrand was not cosmetic. Iru expanded beyond Apple-exclusive management into Windows and Android device support and unified identity, endpoint security, and compliance automation into a single platform, a scope change confirmed independently by Iru’s Wikipedia entry and by Computerworld’s coverage of the announcement.

What Existing Kandji Customers Should Know

Iru’s own FAQ addresses continuity directly, describing the change as “the next evolution of the same company and same team,” and stating there are “no changes on devices managed by Kandji” at the moment of rebrand, with customer tenants and devices upgraded to Iru branding over time rather than all at once. For IT admins mid-contract, that means the console URL, support contacts, and underlying device records carry over, but the product surface area, pricing tiers, and feature roadmap are now built around a broader cross-platform vision than the Apple-only Kandji ever was. Anyone evaluating “Kandji” today based on a review or case study written before October 2025 is looking at a narrower product than what is actually being sold.

Funding and scale disclosures still trace back to the Kandji era. The company’s most recent disclosed raise brought total funding to more than $288 million and pushed its valuation from roughly $800 million to $850 million, and customer-count disclosures across different 2024-2026 sources range from just over 1,000 to roughly 4,000, a spread that likely reflects different counting methodologies (logos versus paid seats versus managed-device thresholds) rather than a single contradiction. Iru has not appeared by name in 2026 Gartner Magic Quadrant leader summaries the way Jamf and Microsoft have, which is worth noting for buyers who weight analyst recognition heavily in procurement scoring.

Full Specs Comparison: Jamf vs Intune vs Iru Side by Side

The table below lines up the three platforms across ownership, platform reach, release cadence, and the analyst and review signals buyers typically weigh during procurement.

CategoryJamf ProMicrosoft IntuneIru (formerly Kandji)
Ownership status (Sept. 2026)Private; Francisco Partners, $2.2B deal closed Jan. 30, 2026Public (Microsoft)Private, VC-backed
Platform focusApple-first: macOS, iOS, iPadOS, tvOS, visionOS, watchOSCross-platform: Windows, Android, iOS, macOSCross-platform since Oct. 2025 rebrand: Apple, Windows, Android
Current release (Sept. 2026)Jamf Pro 11.32.xService release 2609 (in development)Iru platform, post-rebrand product line
Apple OS compatibility listedmacOS/iOS/iPadOS/tvOS/visionOS/watchOS 27.x recommendedActively adding Apple features (Enforce Routes VPN, declarative VPP)Apple management inherited from Kandji; expanded scope not fully itemized publicly
Zero-touch enrollmentApple Business Manager / Apple School ManagerWindows Autopilot plus Apple Business ManagerApple Business Manager integration retained from Kandji
Patch managementStandard MDM patch and update policiesWindows Autopatch with per-update-type approval controls (2026)Endpoint vulnerability management folded into broader Iru scope
Conditional accessVia Microsoft Entra ID integration (updated permissions in 11.30.0)Native Microsoft Entra Conditional AccessIdentity and conditional access unified inside Iru platform
2026 AI / automation featureSelf Service+ (July 2026) with Jamf Security Cloud threat alertsAdvanced Analytics KQL app inventory queries; ChatGPT as protected MAM appMarkets itself as an “AI-powered IT & security platform”
G2 rating (third-party reported)~4.7 / 5, ~400 reviews~4.5 / 5, ~200 reviews~4.8 / 5, ~150 reviews
2026 Gartner Magic QuadrantNamed a LeaderReported among LeadersNot named in 2026 leader summaries
Free tier or trialJamf Now free for up to 3 devices, orgs under 25 employeesNone standalone; bundled with Microsoft 365 E3/E5Free trial only; core product is quote-based
Disclosed scale (2026)75,000+ customers; 32–33M Apple devices managed200M+ devices managed; ~37,119 enterprise customers reported$288M+ total funding; $850M valuation; 1,000–4,000+ customers reported

Pricing Compared: Per-Device Costs and Hidden Fees

None of the three vendors publishes a straightforward, universal price list, which is normal for enterprise MDM but frustrating for anyone trying to build a budget without talking to sales. What is publicly available comes mostly from third-party pricing aggregators and marketplace listings rather than vendor rate cards, so the numbers below should be treated as directional estimates rather than quotes a buyer can lock in.

PlatformReported price rangePricing modelSource basis
Jamf Pro~$3.30–$8.30 per device/month (negotiated to list)Per-device annual licensing, ~$40–$100/device/yearThird-party marketplace pricing analysis
Jamf NowFree for first 3 devices; paid tiers beyond thatPer-device monthly, SMB-focused (under 25 employees)Vendor-published free-tier terms
Microsoft IntuneNo standalone list price commonly publishedBundled in Microsoft 365 E3 / E5 licensingMicrosoft 365 licensing structure
Iru (formerly Kandji)~$2.50–$8 per device/month (community and marketplace estimates)Per-device, quote-based; ~$2,083/mo per product module reported in one estimateThird-party pricing guides; custom quote required

Hidden Costs to Budget For

Per-device sticker prices rarely capture the full bill. Jamf and Iru both charge separately for add-on modules (Jamf Connect, Jamf Protect, and Jamf Security Cloud on one side; Iru’s expanded identity and vulnerability-management modules on the other), so a quote that looks competitive for base MDM can climb once conditional access or endpoint security gets added. Intune’s cost is arguably the hardest to isolate because it rides inside a Microsoft 365 E3 or E5 seat that an organization was likely buying anyway for Exchange, Teams, and SharePoint; the “true” incremental cost of Intune specifically is whatever the E3-to-E5 upgrade delta is, not a number Microsoft publishes as an Intune line item. One 2026 pricing guide also flagged that Iru’s quoted per-module cost can carry additional AWS infrastructure charges depending on deployment size, a detail worth asking about directly during a sales call rather than assuming it is bundled.

Platform Support: Apple-Only Depth vs. Cross-Platform Reach

This is the axis where the three products genuinely diverge rather than just competing on price. Jamf remains the deepest single-vendor option for shops that are Apple hardware top to bottom, including edge cases like visionOS headsets and tvOS-based conference-room displays that neither Intune nor Iru markets support for as explicitly. If an organization’s device fleet is 100% Apple and likely to stay that way, Jamf’s specialization is still a real advantage: features ship for the newest Apple OS versions close to their release, and admin workflows are built around Apple-specific concepts (Smart Groups, Apple Business Manager sync, Declarative Device Management) rather than adapted from a cross-platform base.

Intune sits at the opposite end: it was built Windows-first and has spent years adding credible Apple and Android support on top, rather than the reverse. Its September 2026 preview release still lists new Apple-specific features as forthcoming additions (Enforce Routes VPN support, declarative VPP downloads in the Company Portal), which signals continued investment but also confirms Apple management is still catching up to feature parity with Jamf on some fronts, not leading it. For a mixed Windows-and-Mac enterprise already paying for Microsoft 365 E3 or E5, Intune’s single-console convenience across both operating systems is hard to beat on cost, even if certain Apple-specific capabilities lag a dedicated Apple MDM tool by a release cycle or two.

Iru occupies new middle ground. Before its rebrand, Kandji was arguably the second-most Apple-focused option behind Jamf. Since October 2025, Iru has deliberately walked toward Intune’s cross-platform territory by adding Windows and Android support, positioning itself less as “Jamf’s simpler competitor” and more as a unified alternative to running separate MDM tools per operating system. Whether that expansion has reached genuine feature parity with either Jamf on macOS or Intune on Windows is not yet clear from public documentation, since Iru’s 2026 release notes for the expanded platform were not available in the sources used for this comparison; buyers evaluating Iru specifically for a mixed fleet should ask for platform-by-platform feature parity documentation rather than assuming cross-platform support means equal depth everywhere.

Security and Compliance: Patch Management, Conditional Access, Zero-Touch

Patch and update orchestration is where Intune’s 2026 roadmap has moved the furthest. The Windows Autopatch controls previewed for service release 2609 let admins approve, auto-approve, reject, or schedule quality updates by update type rather than applying a single blanket policy across a fleet, giving security teams more granular control over how quickly a given patch category reaches production machines. Combined with Advanced Analytics extending KQL queries to Windows app inventory, Intune is positioning patch and software-hygiene visibility as a fleet-wide query problem rather than a device-by-device checklist, which scales better for organizations managing tens of thousands of endpoints.

Jamf’s security story in 2026 centers on Jamf Security Cloud and the new Self Service+ mobile client, which layers network security monitoring and centralized threat alerts on top of the existing self-service app catalog. That is a narrower but more Apple-specific security posture than Intune’s Windows-centric Autopatch controls, and it plugs directly into Jamf’s existing device inventory rather than requiring a separate security console. The updated Microsoft Entra ID connection permissions shipped in Jamf Pro 11.30.0 also matter here: organizations running Jamf for device management but Entra ID for identity can now tie conditional access policy more tightly to Jamf-reported device compliance, closing a gap that used to require third-party glue.

Iru’s pitch is consolidation: rather than stitching together a separate MDM tool, identity provider, and vulnerability scanner, the rebrand folds endpoint security, identity, and compliance automation into one system. That is an attractive proposition on paper for a lean IT team that does not want to manage integrations between three or four separate security vendors. The tradeoff is that a single consolidated platform has to be good at all of those functions simultaneously, and Iru has not yet accumulated the years of dedicated conditional-access or patch-management iteration that Intune (via Entra) or Jamf (via Jamf Protect and Jamf Security Cloud) have built up in their respective specialties.

AI and Automation Features Shipped in 2026

Every MDM vendor is now attaching an AI label to some part of its roadmap, but the substance behind that label varies. Intune’s most concrete 2026 AI-adjacent move is treating ChatGPT as a governable, protected app under its mobile application management policies, added in the August 2026 service release. That does not make Intune itself “AI-powered” in a meaningful sense; it means IT admins can now apply data-loss-prevention and access controls to how employees use ChatGPT on managed devices, the same way they would govern any other sanctioned SaaS app. It is a compliance feature wearing an AI headline, not a change to how Intune itself operates.

Jamf’s closest 2026 AI-adjacent feature is Self Service+’s threat-alerting layer through Jamf Security Cloud, which surfaces network-level security signals directly to end users and admins rather than requiring a separate security dashboard. It is more of an automated alerting pipeline than a generative-AI feature, but it does reduce the manual correlation work a security analyst would otherwise do between a network security tool and the MDM console.

Iru is the only one of the three explicitly branding itself around AI at the company level, describing itself in its own rebrand announcement as “the AI-powered IT & security platform used by the world’s fastest-growing companies.” Public documentation on exactly which workflows that AI branding covers, beyond the general consolidation of identity, endpoint security, and compliance automation, was not available in the sources used here. Buyers who care specifically about generative-AI or machine-learning-driven automation (as opposed to consolidated dashboards marketed as “AI-powered”) should ask Iru’s sales team for concrete examples of what the AI layer actually automates before treating that branding as a differentiator on its own.

Benchmarks: Ratings, Analyst Recognition, and Platform Coverage

Beyond price and features, buyers tend to lean on two outside signals: user review aggregators like G2, and analyst reports like Gartner’s Magic Quadrant. Both come with caveats worth stating plainly. The G2 figures below are drawn from third-party MDM comparison pages that cite G2 scores rather than G2’s live product pages directly, so treat them as widely repeated secondary figures rather than a confirmed, current snapshot.

SignalJamf ProMicrosoft IntuneIru (formerly Kandji)
G2 rating (third-party reported)~4.7 / 5~4.5 / 5~4.8 / 5
G2 review volume (third-party reported)~400 reviews~200 reviews~150 reviews
2026 Gartner Magic Quadrant for Endpoint Management ToolsNamed a LeaderReported among LeadersNot named in leader summaries surfaced
tvOS / visionOS supportYes, listed in Sept. 2026 system requirementsNot advertisedNot advertised
Native Windows supportServer hosting only; not an endpoint OS targetYes, core platformYes, added Oct. 2025
Native Android supportLimitedYes, core platform (Managed Home Screen, Entra shared device mode)Yes, added Oct. 2025

The pattern that falls out of this table is straightforward: Jamf wins on Apple-specific platform depth and analyst recognition, Intune wins on native cross-platform reach and its own Gartner standing, and Iru’s review scores look competitive on paper but lack the same level of independent analyst validation the other two have accumulated. None of that means Iru is a worse product; it means Iru is newer to the consolidated cross-platform category it now competes in, and buyers should weight that recency accordingly.

Real-World Deployment Patterns: 5 Examples

Named customer case studies with disclosed device counts are hard to come by for any of these three vendors publicly, but the deployment patterns below are drawn from documented, sourced scale figures and one confirmed named institution rather than invented examples.

Deployment typePlatform typically chosenDocumented detail
University system, Apple-managed campus fleetKandji / now IruUniversity of Alaska’s Mac fleet ran on Kandji and was migrated to Iru branding automatically following the October 2025 rebrand, per the university’s own IT notice to staff
Aggregate enterprise Apple fleet managementJamf Pro75,000+ organizations reportedly manage 32–33 million Apple devices on Jamf globally as of 2026
Mixed Windows/Mac enterprise on Microsoft 365Microsoft Intune200 million-plus devices reportedly managed through Intune, scaled through Microsoft 365 E3/E5 bundling rather than standalone MDM sales
Small business or startup under 25 employeesJamf Now (free tier)Jamf Now manages up to 3 devices free, aimed specifically at organizations under 25 employees
Fast-growing, cross-platform startupIruIru markets itself directly at “the world’s fastest-growing companies” needing unified Windows, Android, and Apple management post-rebrand

5 Use Cases: Which MDM Platform Fits Your Organization

  • All-Apple enterprise with tvOS or visionOS hardware: Jamf Pro is still the only one of the three with explicitly documented tvOS and visionOS support in its current system requirements, making it the safer pick for organizations running Apple TV signage or Vision Pro deployments alongside standard Mac and iPhone fleets.
  • Mixed Windows-and-Mac shop already paying for Microsoft 365 E3/E5: Intune’s bundled pricing and native Entra Conditional Access integration make it the lowest-incremental-cost option, since the organization is typically already paying for the license tier that includes it.
  • Lean IT team wanting device management, identity, and vulnerability scanning in one console: Iru’s post-rebrand consolidation is built for exactly this scenario, trading some category-specific depth for fewer vendor integrations to maintain.
  • Small business or school under 25 employees with three or fewer devices: Jamf Now’s free tier removes the cost barrier entirely for the smallest deployments, before a business needs to graduate to full Jamf Pro.
  • Enterprise procurement teams that weight analyst recognition heavily: Jamf’s and Microsoft’s 2026 Gartner Magic Quadrant Leader positioning gives risk-averse buyers an independent validation point that Iru does not yet have in the same report.
  • Organizations prioritizing Windows-side patch granularity: Intune’s 2026 Autopatch controls, letting admins approve or reject updates by category, are the most fleet-scale-friendly patch tooling of the three as documented here.

Migration Guide: Moving Between Jamf, Intune, and Iru

Switching MDM platforms is disruptive by design, since every enrolled device has to be re-supervised under the new tool’s management framework. The steps below outline the general sequence IT teams use regardless of which direction the migration runs.

  1. Export a full device inventory from the current platform, including serial numbers, assigned users, and installed configuration profiles, before touching anything in the destination tool.
  2. Reassign the Apple Business Manager or Apple School Manager MDM server token from the old platform to the new one; this is the step that actually controls which console owns zero-touch enrollment going forward.
  3. Rebuild configuration profiles (Wi-Fi, VPN, restrictions, app deployment policies) in the destination platform rather than assuming an automated import tool will translate them cleanly, since policy structures differ meaningfully between Jamf, Intune, and Iru.
  4. Run a pilot group of 10-20 devices through full re-enrollment before touching the production fleet, watching specifically for conditional-access or Entra ID integration breakage.
  5. Communicate a specific re-authentication window to end users, since most platform migrations force at least one supervised re-enrollment prompt on each device.
  6. Stagger the production rollout by department or device type rather than migrating the entire fleet in one push, so helpdesk ticket volume stays manageable.
  7. Decommission the old platform’s management profile only after confirming the new platform shows the device as fully compliant, to avoid a gap where neither tool is actively enforcing policy.

Pulling a clean inventory export before migration matters more than any other step, since it is the fallback record if a configuration profile fails to translate correctly. A simple Jamf Pro Classic API call can pull a full computer inventory as a starting point:

curl -X GET \
  "https://yourinstance.jamfcloud.com/JSSResource/computers" \
  -H "Accept: application/json" \
  -u "api_username:api_password" \
  -o jamf_device_inventory.json

The equivalent pull from Intune runs through Microsoft Graph rather than a REST endpoint tied to a single cloud instance, reflecting the platform’s broader Microsoft 365 integration:

GET https://graph.microsoft.com/v1.0/deviceManagement/managedDevices
Authorization: Bearer {access_token}
Accept: application/json

Neither export replaces a full backup of configuration profiles and scripts, but both give a migration team a device-by-device checklist to confirm nothing gets lost in the transition, and a rollback reference if the pilot group surfaces problems before the production migration begins.

Pros and Cons of Each Platform

Jamf Pro

  • Pros: Deepest Apple OS coverage including tvOS and visionOS; active 2026 release cadence; named a 2026 Gartner Leader; free entry tier via Jamf Now for very small teams.
  • Cons: Now privately held, removing public financial transparency; weaker native Windows and Android support than Intune or Iru; add-on modules (Connect, Protect, Security Cloud) add cost on top of base licensing.

Microsoft Intune

  • Pros: Bundled into Microsoft 365 E3/E5 licensing many orgs already own; native Entra Conditional Access; strongest 2026 patch-management granularity via Windows Autopatch; largest reported device scale.
  • Cons: Apple-specific features still catching up to Jamf on some fronts; no meaningful standalone free tier; true incremental cost is hard to isolate from broader Microsoft 365 spend.

Iru (formerly Kandji)

  • Pros: Consolidates MDM, identity, and vulnerability management in one console; expanded to Windows and Android in Oct. 2025; highest third-party-reported G2 rating of the three.
  • Cons: Not yet named in 2026 Gartner Magic Quadrant leader summaries; no free tier; brand confusion risk since search results and old reviews still reference “Kandji”; cross-platform feature parity not yet fully documented publicly.

The Verdict: Which MDM Platform Wins in 2026

There is no single winner across all three, because the products are no longer solving quite the same problem. For an all-Apple fleet that includes edge-case hardware like Vision Pro headsets or Apple TV signage, Jamf Pro’s documented tvOS and visionOS support, its 2026 Gartner Leader status, and its 75,000-plus customer base managing 32-33 million devices make it the safest, most specialized pick, even accounting for the reduced financial transparency that comes with its move to private ownership under Francisco Partners.

For any organization already paying for Microsoft 365 E3 or E5, Intune’s bundled pricing is difficult to argue against on cost alone, and its 2026 Autopatch and Advanced Analytics additions show a platform actively investing in Windows-fleet scale rather than coasting on bundling advantage. Its reported 200 million-plus managed devices reflect that default-choice dynamic more than a head-to-head feature win, but for budget-constrained IT teams, “already included” beats “best in category” often enough that Intune remains the pragmatic default for mixed fleets.

Iru is the platform to evaluate carefully rather than dismiss or default to. Its October 2025 expansion from Apple-only Kandji into cross-platform identity, endpoint security, and compliance automation is a genuinely different pitch than either competitor: one console instead of three or four point tools. The risk is recency. Iru has not yet accumulated the multi-year analyst recognition or the deep, OS-specific feature history that Jamf and Intune both have, and buyers should ask pointed questions about platform-by-platform feature parity rather than assuming “AI-powered” branding or a strong G2 score substitutes for that track record. For fast-growing, cross-platform companies willing to be early adopters of a consolidated model, Iru is worth a serious trial. For risk-averse enterprise procurement teams, Jamf or Intune remain the lower-variance choices in 2026.

Frequently Asked Questions

Is Kandji still called Kandji in 2026?

No. Kandji rebranded to Iru on October 22, 2025, expanding from Apple-only device management into Windows and Android support alongside unified identity and compliance automation. Existing customers were carried over automatically, with tenants and devices upgraded to Iru branding over time.

Did Jamf really go private?

Yes. Francisco Partners closed a $2.2 billion all-cash acquisition of Jamf on January 30, 2026, at $13.05 per share, taking the company off public markets. Jamf’s product releases have continued on a similar cadence since the deal closed.

Which is cheaper, Jamf, Intune, or Iru?

Third-party estimates put Jamf Pro at roughly $3.30-$8.30 per device per month and Iru at roughly $2.50-$8 per device per month, both quote-based. Intune has no standalone list price since it ships bundled inside Microsoft 365 E3/E5 licensing, so its effective cost depends on what license tier an organization already needs.

Does Microsoft Intune support macOS as well as Jamf does?

Intune supports macOS management, but Jamf’s Apple-specific feature depth, including tvOS and visionOS support listed in its September 2026 system requirements, remains broader than Intune’s current documented Apple feature set.

Can Jamf and Intune be used together?

Yes. Jamf Pro 11.30.0 shipped updated Microsoft Entra ID connection permissions specifically to tie Jamf-managed device compliance into Entra Conditional Access policy, a common setup for organizations that want Jamf’s Apple management depth alongside Microsoft’s identity and Windows-side tooling.

What happened to existing Kandji customers after the Iru rebrand?

According to Iru’s own FAQ, existing Kandji deployments were not disrupted at the moment of the rebrand; devices and tenants are being migrated to Iru branding over time, and the underlying company and team remain the same.

Which MDM platform has the best G2 rating?

Third-party comparison sites report Iru at roughly 4.8 out of 5, ahead of Jamf Pro’s roughly 4.7 and Intune’s roughly 4.5, though Iru’s review volume (around 150) is lower than Jamf’s (around 400), and these figures come from secondary sources rather than confirmed live G2 pages.

Is there a free MDM option for small businesses?

Jamf Now offers free management for up to 3 devices for organizations under 25 employees, the only genuinely free tier among the three platforms covered here. Neither Intune nor Iru offers a comparable standalone free tier as of September 2026.

Related Coverage

Sofia Lindström

Sofia Lindström

Editor-in-Chief

Sofia Lindström is the Editor-in-Chief at Tech Insider, where she leads editorial strategy and oversees coverage across AI, cybersecurity, and enterprise technology. With over a decade in Swedish tech journalism, she previously served as technology editor at Dagens Industri and covered the Nordic startup ecosystem for Breakit. Sofia holds an MSc in Media Technology from KTH Royal Institute of Technology and is a frequent speaker at Web Summit and Slush. She is passionate about making complex technology accessible to business leaders.

View all articles