Jamf vs Microsoft Intune: Which Device Management Platform Fits Your Fleet in 2026?

Turn this article into takeaways for your work.
Each assistant summarizes the article only for you and suggests best practices for your work.
Updated August 2026
Almost every comparison of these two platforms opens with a price table. Ours can't, and that fact turns out to be the most useful thing on this page.
Microsoft publishes what Intune costs down to the individual add-on. Jamf publishes nothing. jamf.com/pricing lists Jamf for Mac, Jamf for Mobile, Jamf Pro, Jamf School, Jamf Connect, Jamf Protect and Jamf Now, then closes with a line telling you to "Contact a Jamf representative or your local authorized reseller for a detailed quote in your local currency." There is not one dollar figure on the page. The $4.17 per device per month that dozens of comparison articles still repeat as Jamf Pro's price is not there, and buyer contract data suggests it hasn't been close to reality for some time.
Then there's the second problem, which nobody puts in a table at all. Intune bills per user. Jamf bills per device. A designer with a MacBook, an iPhone and an iPad is one Intune unit and three Jamf units. Any comparison that puts "$8" next to "$4.17" in the same row is comparing two different things, and it gets the arithmetic wrong before it gets the conclusion wrong.
This page is for the IT director, systems admin or CIO who has narrowed the shortlist to these two and needs to know what each one does, what each one costs against your fleet shape, and whether the honest answer is "both." Every figure below is either taken from the vendor's own page or labelled (reported) with its source named.
TL;DR
| Jamf | Microsoft Intune | |
|---|---|---|
| What it is | Apple-first management and security platform (Jamf Pro, Jamf Now, Jamf School, plus Connect and Protect) | Cross-platform unified endpoint management inside the Microsoft 365 and Entra stack |
| Billing basis | Per device, per month | Per user, per month |
| Published price | None. The pricing page carries no dollar figures and points you to a rep or reseller | Fully published, Plan 1 at $8.00 per user per month, paid yearly |
| Free entry point | Jamf Now: "Manage up to 3 devices for free" | Trial only, no free tier |
| Platforms covered | macOS, iOS, iPadOS, tvOS, visionOS, watchOS | Windows, macOS, iOS/iPadOS, Android, Linux (Ubuntu and RHEL), Chrome OS |
| Windows management | No | Yes, including Windows Autopilot |
| Apple OS day-one support | Same-day support for Apple's fall releases, "14 consecutive years" per Jamf | Day zero support for iOS/iPadOS and macOS 26, per Microsoft's Intune team |
| Scripting depth | Shell scripts with event triggers, extension attributes, Smart Groups | Shell scripts under 1 MB, agent check-in every 8 hours, custom attribute output capped at 20KB |
| Endpoint security | Jamf Protect, macOS, iOS and visionOS only | Defender for Endpoint across Windows, macOS, Linux, Android and iOS, licensed separately |
| Identity and conditional access | Reports compliance into Microsoft Entra ID through the Jamf Device Compliance connector | Native, it is the Entra Conditional Access signal source |
| Owner | Francisco Partners, private since 30 January 2026 | Microsoft |
| Best for | Apple-heavy fleets where Mac configuration depth and day-one OS support are the actual job | Mixed fleets already paying for Microsoft 365, where one console and one identity beat per-platform depth |
| Worst for | Any Windows device, and small teams that need a budget number before a sales call | Teams whose whole value is deep, scripted, event-driven Mac workflows |
The short verdict. If your fleet is majority Apple and Mac configuration depth is the actual job, Jamf is still the better product, and you will have to sit through a sales call to find out what it costs. If your fleet is mixed and you already pay for Microsoft 365 E3 or E5, Intune is the cheaper and simpler answer because you have already bought it. And if you are Apple-heavy inside a Microsoft shop, the honest answer is frequently both, with Jamf managing the Macs and Intune acting as the compliance authority for Entra Conditional Access. That combination is a real, documented architecture. It is also the most expensive of the three.

Key Facts
- Jamf has been a private company since 30 January 2026. Francisco Partners completed its acquisition that day at $13.05 per share, an enterprise value of roughly $2.2 billion, and Jamf stock was delisted from Nasdaq, per the closing announcement carried on Business Wire. Jamf said in its own October 2025 release that it "will continue to operate under the Jamf name."
- Jamf publishes no per-device price at all. Its pricing page names ten products and carries zero dollar figures, directing buyers to "Contact a Jamf representative or your local authorized reseller." The only price Jamf does publish sits on the Jamf Now product page: "Manage up to 3 devices for free."
- Buyer contract data puts Jamf Pro far above the figure listicles repeat. Procurement platform Vendr's Jamf marketplace page reports observed rates of "$8-$20+ per device per month" for Jamf Pro depending on volume, alongside a median Jamf contract of $30,155 a year drawn from 687 purchases. Vendr sells negotiation services, so read this as buyer-side observed pricing rather than a list price. It is still a great deal closer to what buyers report paying than the $4.17 still in circulation.
- Intune's packaging changed in July 2026, in buyers' favour. Microsoft's Intune pricing page now states that select advanced Intune capabilities are included in Microsoft 365 E3 and E5 from July 2026. E3 picks up Intune Plan 2, Remote Help and Advanced Analytics; E5 adds Endpoint Privilege Management, Microsoft Cloud PKI and Enterprise Application Management on top. Bought standalone, those six items list at $4.00, $3.50, $5.00, $3.00, $2.00 and $2.00 per user per month respectively.
- For an SMB, "you already own Intune" is a $22 per user per month argument. Microsoft's Business Premium page lists Microsoft 365 Business Premium at "$22.00 user/month, paid yearly," and it is the cheapest Microsoft 365 business plan that bundles Intune Plan 1 for "device and app administration across platforms." The same page carries "$26.40 user/month with a monthly subscription," $18.79 paid yearly without Teams, and $32.00 paid yearly for the Copilot variant. Business Basic, Business Standard and Business Premium all "support a maximum of 300 users," so above that headcount you are looking at the enterprise E-series or standalone Intune instead.
The Pricing Asymmetry Nobody Puts in the Comparison Table
Here is what each vendor actually publishes today, and what has to be labelled.
| Item | Basis | Published price | Evidence class |
|---|---|---|---|
| Microsoft Intune Plan 1 | Per user, per month, paid yearly | $8.00 | Vendor page (pricing FAQ) |
| Microsoft Intune Plan 2, requires Plan 1 | Per user, per month, paid yearly | $4.00 | Vendor page |
| Microsoft Intune Suite, requires Plan 1 | Per user, per month | $10.00 | Vendor page |
| Intune Remote Help, requires Plan 1 | Per user, per month, paid yearly | $3.50 | Vendor page |
| Intune Endpoint Privilege Management, requires Plan 1 | Per user, per month, paid yearly | $3.00 | Vendor page |
| Intune Advanced Analytics, requires Plan 1 | Per user, per month, paid yearly | $5.00 | Vendor page |
| Intune Enterprise Application Management, requires Plan 1 | Per user, per month, paid yearly | $2.00 | Vendor page |
| Microsoft Cloud PKI, requires Plan 1 | Per user, per month, paid yearly | $2.00 | Vendor page |
| Microsoft 365 Business Standard, paid yearly (no Intune) | Per user, per month | $14.00 | Vendor page |
| Microsoft 365 Business Standard with Copilot, paid yearly (no Intune) | Per user, per month | $23.50 | Vendor page |
| Microsoft 365 Business Premium, paid yearly | Per user, per month | $22.00 | Vendor page |
| Microsoft 365 Business Premium, monthly billing | Per user, per month | $26.40 | Vendor page |
| Microsoft 365 Business Premium with Copilot, paid yearly | Per user, per month | $32.00 | Vendor page |
| Microsoft 365 E3, with Teams / no Teams | Per user, per month, paid yearly | $39.00 / $30.45 | Vendor page |
| Microsoft 365 E5, with Teams / no Teams | Per user, per month, paid yearly | $60.00 / $51.45 | Vendor page |
| Jamf Now, first three devices | Per device, per month | Free, "Manage up to 3 devices for free" | Vendor page |
| Jamf Now, device four and beyond | Per device, per month | Not published | Absent from the vendor site |
| Jamf Pro | Per device, per month | Not published | Absent. Observed at $8-$20+ (reported, Vendr) |
| Jamf Protect | Per device, per month | Not published | Absent. Observed at $3-$8 per Mac (reported, Vendr) |
| Jamf Connect | Per device, per month | Not published | Absent. Observed at $2-$5 per Mac (reported, Vendr) |
| Jamf for Mac and Jamf for Mobile bundles | Per device, per month | Not published, "Contact Us" | Vendor page |
Two things about that table deserve saying plainly.
First, the circulating Jamf numbers do not agree with each other. Search for Jamf Pro pricing and you will find $4.17, $6.25, $8.25, $12.50 and $13.33 per device per month stated with equal confidence on different pages, none traceable to a Jamf URL that currently exists. That spread isn't one writer being sloppy. It's what happens when a vendor stops publishing and a hundred pages keep quoting each other's cached copy of a number that was last true years ago. If you see a Jamf price presented as fact anywhere, including here, check whether the source names a live Jamf page.
Second, Microsoft's transparency has a catch. The $8.00 Plan 1 rate is real and buyable standalone, but hardly anyone buys it that way. Most organisations get Intune inside a Microsoft 365 bundle, and the bundle price is where the money sits. That is the number to model.
Per User or Per Device: The Unit Mismatch That Breaks Most Comparisons
This is the part that changes answers, so it's worth being concrete.
Intune licences a person. Microsoft's own enrollment restriction documentation confirms the device limit per user "from 1 to 15," meaning one licensed user can enrol up to fifteen devices under a single seat depending on how you configure the restriction. Jamf licences a device. Every Mac, iPhone, iPad and Apple TV is its own line on the invoice.
| Person | Devices | Intune units | Jamf units |
|---|---|---|---|
| Warehouse supervisor, one shared iPad | 1 | 1 | 1 |
| Sales rep, laptop and phone | 2 | 1 | 2 |
| Designer, MacBook, iPhone, iPad | 3 | 1 | 3 |
| Field engineer, laptop, phone, tablet, Apple TV in the van | 4 | 1 | 4 |
| 25-person studio, one Mac each | 25 | 25 | 25 |
| 25-person studio, one Mac and one iPhone each | 50 | 25 | 50 |
The ratio between the two columns is your whole comparison. At a device-to-user ratio of 1.0, the two billing models behave the same way and you can compare rates directly. At 2.0, Jamf's effective per-person cost doubles while Intune's stays flat. At 3.0 it triples. This is why Jamf tends to look competitive in Mac-only laptop refreshes and expensive in fleets where everybody also carries a company iPhone and an iPad.
Two caveats keep this honest. Intune's device limit is a configurable restriction, not a licensing guarantee, and Microsoft is explicit that "an Intune license is required for any user or device that benefits directly or indirectly from the Microsoft Intune service." Shared and kiosk devices with no assigned user need Intune's separate device-only subscription, which does not support Conditional Access or app protection policies. So the per-user model is genuinely cheaper for the one-person-many-devices case and genuinely awkward for the many-people-one-device case. Jamf's per-device model is the mirror image.
What Three Real Fleets Actually Cost
Every cell states its unit basis, every Jamf figure is a labelled band rather than a price, and Microsoft figures are vendor-published annual-billing rates converted to twelve months. Nothing here is a quote.

Fleet A: a 25-person creative studio, 25 Macs, one device each. Device-to-user ratio 1.0.
| Option | Unit basis | Monthly | Annual | Notes |
|---|---|---|---|---|
| Intune Plan 1 standalone | 25 users at $8.00 | $200 | $2,400 | Device management only, no Office, no email |
| M365 Business Premium | 25 users at $22.00 | $550 | $6,600 | Includes Office, email, security, Intune Plan 1 |
| M365 Business Premium with Copilot | 25 users at $32.00 | $800 | $9,600 | Same plan, Copilot variant |
| Jamf Pro (reported band) | 25 devices at $8-$20+ | $200-$500+ | $2,400-$6,000+ | Not published, Vendr-observed range |
| Mosyle Business FREE | 30 devices, free | $0 | $0 | Free up to 30 devices, vendor-published |
| Mosyle Business Premium | 30-licence minimum at $1.00 | $30 | $360 | Vendor-published, billed annually |
Fleet B: the same 25 people, now with a company iPhone each. 50 Apple devices, ratio 2.0.
| Option | Unit basis | Monthly | Annual | Change vs Fleet A |
|---|---|---|---|---|
| Intune Plan 1 standalone | 25 users at $8.00 | $200 | $2,400 | No change |
| M365 Business Premium | 25 users at $22.00 | $550 | $6,600 | No change |
| Jamf Pro (reported band) | 50 devices at $8-$20+ | $400-$1,000+ | $4,800-$12,000+ | Doubles |
| Mosyle Business Premium | 50 devices at $1.00 | $50 | $600 | Up 67% from the 30-licence floor |
Fleet C: 200 people, mixed platform. 150 Windows laptops, 50 Macs, 150 company iPhones, 350 devices total.
| Option | Unit basis | Monthly | Annual | Covers |
|---|---|---|---|---|
| Intune Plan 1 standalone | 200 users at $8.00 | $1,600 | $19,200 | All 350 devices, all platforms |
| M365 Business Premium | 200 users at $22.00 | $4,400 | $52,800 | Still available at 200 people, the plan caps at 300 users |
| M365 E3 with Teams | 200 users at $39.00 | $7,800 | $93,600 | Office, email, security, Intune Plan 1 and Plan 2 |
| Jamf Pro on Apple only (reported band) | 100 Apple devices at $8-$20+ | $800-$2,000+ | $9,600-$24,000+ | Macs and iPhones only, no Windows |
| Both: Intune Plan 1 plus Jamf on Apple | 200 users plus 100 devices | $2,400-$3,600+ | $28,800-$43,200+ | Everything, with Jamf depth on Apple |
Four readings come out of those tables.
At ratio 1.0 the two products land in genuinely overlapping territory, and the deciding factor is capability, not cost. At ratio 2.0 Jamf's bill doubles while Intune's does not move at all, which is the single most under-reported fact in this comparison. In the mixed fleet, Jamf cannot be the whole answer at any price, because it does not manage Windows. The relevant question there isn't Jamf or Intune, it's Intune alone or Intune plus Jamf, and the premium for adding Jamf on 100 Apple devices lands somewhere around $10,000 to $24,000 a year on reported rates.
The fourth reading is inside the Microsoft column, and it catches people out. At 200 people you are still under Business Premium's 300-user ceiling, so the gap between $52,800 and $93,600 a year is $40,800 for two plans that both include Intune Plan 1. E3 buys plenty besides device management, but if endpoint management is why you are looking at E3, price the cheaper plan first.
If you want a repeatable way to build this out for your own numbers, our guide to TCO modelling for SaaS walks through the same exercise with add-ons, ramp and renewal uplift folded in.
Same-Day Apple OS Support
This was Jamf's cleanest differentiator for years, and it is the claim most competing comparisons repeat without checking. Worth checking, because the gap has narrowed.

Jamf's position is documented and specific. On 15 September 2025 the company announced same-day support for macOS Tahoe 26, iOS 26, iPadOS 26, tvOS 26, visionOS 26 and watchOS 26 on the day they went generally available, marking "14 consecutive years of offering same-day support." That is Jamf's own claim about Jamf, though the track record behind it is long and publicly checkable.
Microsoft's position has moved. Its Intune Customer Success team published a day zero support post for the same OS 26 wave, stating that existing features work as expected on release day and that the settings catalog was updated for newly released iOS/iPadOS and macOS settings across both declarative device management and classic MDM. Microsoft also raised Intune's floor with that release: its supported platforms reference lists "iOS/iPadOS 17.x and later" and "macOS 14.x and later" as supported, with older versions merely "Allowed to enroll."
| Question | Jamf | Intune |
|---|---|---|
| Existing management works on day one | Yes, claimed 14 consecutive years | Yes, day zero support stated for OS 26 |
| New OS settings exposed on day one | Yes, across the platform | Settings catalog updated for the release wave |
| Declarative device management support | Yes, Blueprints built on DDM | Yes, settings catalog covers DDM and MDM |
| Supported OS floor today | Tracks Apple's current releases | iOS/iPadOS 17 and later, macOS 14 and later |
| Brand-new hardware and headline features | Historically first to market | Historically trails on the newest niche capabilities |
The honest 2026 read: "Jamf supports new Apple releases on day one and Intune doesn't" no longer holds as a blanket statement. Both vendors commit to day-one functionality now. Where Jamf still leads is at the edges, the brand-new WWDC capability only a specialist platform bothers to surface in its first quarter. If you adopt new Apple features the week they ship, that edge matters. If you mostly need last year's features to keep working, it doesn't.
macOS and iOS Configuration Depth
This is where Jamf's advantage is real, current and measurable, and where Intune's documentation quietly does the arguing for you.

Intune runs macOS shell scripts through its own management agent, and Microsoft publishes the constraints: the script file "must be less than 1 MB in size", scripts running longer than 60 minutes "are stopped and reported as failed," the agent check-in "occurs every 8 hours," and a script re-runs only when you configure a retry count and the previous run failed. Custom attributes, Intune's answer to Jamf's extension attributes, "are run every 8 hours on managed Macs" and the returned result "must be 20KB or less."
Jamf Pro's model differs in kind, not just degree. Policies fire on event triggers rather than a fixed check-in window, extension attributes feed directly into Smart Groups, and Smart Group membership drives scope automatically. That chain, collect a custom data point, group on it, act on the group, is what Mac admins mean when they say Jamf does something Intune doesn't. Jamf's product page names the pieces: Zero-touch deployment, Self Service+ where "users can install apps, update software and maintain their own devices," Smart Groups, and Blueprints for managing "across all your Apple devices with Declarative Device Management."
| Capability | Jamf Pro | Intune |
|---|---|---|
| Shell scripts on macOS | Yes, with event triggers | Yes, file must be under 1 MB, agent checks in every 8 hours |
| Script run frequency control | Trigger-based and scheduled | Frequency setting plus retry on failure only |
| Custom inventory data collection | Extension attributes | Custom attributes, output capped at 20KB, run every 8 hours |
| Group devices by that custom data | Yes, Smart Groups consume extension attributes | Not supported for custom attributes |
| Report on or API-update that custom data | Yes | Limited |
| End-user self-service catalogue | Yes, Self Service+ | Company Portal |
| Declarative device management | Yes, Blueprints | Yes, via the settings catalog |
| Long-running task ceiling | Not a published hard limit | Scripts over 60 minutes are killed and marked failed |
If your Mac management is mostly profiles, app deployment, FileVault and compliance, Intune covers it and the gap is theoretical. If your Mac management involves conditional workflows keyed off custom inventory data, the gap is your daily job and Jamf wins on the merits.
Windows, Android and Linux Coverage
This section is short because the answer is one-sided.
Jamf does not manage Windows. It never has, and Jamf Protect covers "macOS, iOS and visionOS" with no Windows or Android in the platform list. Intune's supported platform reference covers Android, iOS/iPadOS, Linux, macOS, Windows and Chrome OS, including Ubuntu LTS 24.04 and 26.04, Red Hat Enterprise Linux 9 and 10, and every Android Enterprise management mode from personally owned work profile through fully managed and dedicated.
| Platform | Jamf | Intune |
|---|---|---|
| macOS | Yes, the core product | Yes, macOS 14 and later supported |
| iOS and iPadOS | Yes | Yes, iOS/iPadOS 17 and later supported |
| tvOS, visionOS, watchOS | Yes | Not listed in Intune's supported OS reference |
| Windows 10 and 11 | No | Yes, including Autopilot and co-management |
| Windows 365 Cloud PCs | No | Yes |
| Android Enterprise | No | Yes, all modes including AOSP |
| Linux | No | Ubuntu 24.04 and 26.04 LTS, RHEL 9 and 10 |
| Chrome OS | No | Yes, app protection policies excepted |
For a mixed fleet this settles the base-layer question on its own. Jamf can be a specialist layer on top of something else. It cannot be the only thing you run. Anyone weighing the broader estate should read this alongside our best SaaS management software roundup, since device management and SaaS licence management are separate purchases budget owners routinely confuse.
Zero-Touch Enrollment
Both platforms do zero-touch on Apple, and both do it through Apple's own machinery, so the differences are in what happens after the device finishes setup, not during it.
| Enrollment path | Jamf | Intune |
|---|---|---|
| Apple Automated Device Enrollment, with user affinity | Yes | Yes |
| Apple ADE without user affinity, shared or kiosk devices | Yes | Yes, but needs a device-only subscription for unassigned devices |
| Apple Configurator | Yes | Yes |
| Apple School Manager | Yes, plus the dedicated Jamf School product | Yes |
| BYOD or personal device enrollment | Yes, including BYOD zero-touch on Jamf Pro | Yes, personally owned devices classified as such by default |
| Windows Autopilot | No | Yes, self-deploying and pre-provisioned modes |
| Post-enrollment configuration model | Blueprints and policies, event-triggered | Configuration profiles, settings catalog, compliance policies |
One nuance worth knowing before you plan a rollout: Intune classifies both macOS and iOS/iPadOS devices as personally owned by default. To count as corporate-owned, a Mac has to be registered by serial number or enrolled via Apple ADE. Get that wrong and your ownership-based policy targeting silently misses devices.
Identity and Conditional Access
Here the asymmetry flips. Intune is not just integrated with Microsoft Entra Conditional Access, it is the thing Conditional Access reads from. Jamf has to be plumbed in.
Microsoft's documentation is unusually blunt about what changed. The Jamf managed device compliance page carries an Important notice: "Jamf macOS device support for Conditional Access is being deprecated. Beginning on January 31, 2025, the platform that Jamf Pro's Conditional Access feature is built on will no longer be supported." The old path under Settings, Global, Conditional Access "is no longer able to accept new configurations." New integrations go through Settings, Global, Device Compliance instead, via a wizard that creates two Entra app registrations. The mechanics have consequences worth pricing in before you commit.
| Consideration | Jamf plus Intune compliance connector | Intune managing Macs directly |
|---|---|---|
| Where the compliance signal originates | Jamf Smart Group membership, pushed to Entra ID | Intune compliance policy |
| Do Jamf-managed Macs appear in the Intune device list | No, Microsoft states they don't | Yes |
| Setup artefacts required | Two Entra app registrations, two Jamf Smart Groups, one Jamf policy, Company Portal deployed via the Jamf App Catalog | None beyond normal enrollment |
| How users register | Through the Jamf Self Service app policy | Through Company Portal |
| Common failure mode | User registers via Company Portal instead of Self Service and hits an AccountNotOnboarded error | Not applicable |
| Conditional Access policy work | The User Registration app must be excluded from any policy requiring a compliant device | Standard |
| Compliance refresh cadence | Follows the Jamf Compliance Smart Group's own update frequency | Intune's own evaluation cycle |
None of that is a reason to avoid running both. Plenty of large Apple estates do exactly this. But it is four or five moving parts that a single-vendor deployment doesn't have, and every one of them is a place a rollout stalls. If you're formally scoring this decision, our SaaS vendor evaluation scorecard is a reasonable frame for weighting integration burden against capability.
Patching and App Lifecycle
Both platforms patch. The difference is which side of the fleet each one is genuinely good at.

Jamf's app lifecycle management sits on the Jamf App Catalog, which Microsoft's own documentation recommends using to keep the Intune Company Portal app current on Jamf-managed Macs, a small but telling endorsement. Jamf handles macOS updates through declarative software update management and its own patch policies, and Self Service+ lets users update software themselves rather than waiting on a maintenance window.
Intune's newest strength here is Enterprise Application Management, which deploys "curated Win32 apps from a Microsoft-hosted Enterprise App Catalog with built-in install settings." Note the scope carefully: Win32, which means Windows. It is a genuinely useful capability and it is not a Mac capability. Intune patches macOS through Apple's software update mechanisms and deploys Mac apps as DMG, PKG or LOB packages, which works, but the curated catalogue advantage is on the Windows side.
| Patching capability | Jamf | Intune |
|---|---|---|
| Curated third-party app catalogue for macOS | Yes, Jamf App Catalog | No equivalent curated macOS catalogue |
| Curated third-party app catalogue for Windows | Not applicable | Yes, Enterprise App Catalog, Win32 apps, requires Plan 1 |
| macOS OS update enforcement | Yes, declarative software update management | Yes, managed software updates |
| Windows Update for Business rings | No | Yes |
| End-user initiated updates | Yes, Self Service+ | Company Portal |
| Vulnerability and CVE reporting | Yes, via Jamf Protect | Via Defender Vulnerability Management, licensed separately |
Security Posture: Jamf Protect vs Defender for Endpoint
Both vendors sell endpoint security as a separate line item, and both are decent. The split is coverage versus specialisation.

Jamf Protect is built on Apple's own frameworks. Jamf's product page states it "uses the Apple endpoint security API and other native frameworks across macOS, iOS and visionOS," and lists telemetry to SIEM, CVE-based vulnerability management, advanced threat controls against fileless attacks, next-gen antivirus, removable storage controls, jailbreak detection, content filtering and phishing protection. What that list does not contain is Windows or Android.
Microsoft Defender for Endpoint runs on "Windows, macOS, Linux, Android, and iOS" per Microsoft Learn, which also states that "Microsoft 365 E5 and Microsoft 365 E5 Security include Defender for Endpoint Plan 2." So the E5 shop that already pays $60.00 per user per month has EDR on every platform already bought, which is a materially different starting position from an Apple-only shop pricing Jamf Protect as a fresh line item at a reported $3-$8 per Mac per month.
| Security dimension | Jamf Protect | Defender for Endpoint |
|---|---|---|
| macOS | Yes, built on Apple's endpoint security API | Yes |
| iOS and visionOS | Yes | iOS yes, visionOS not listed |
| Windows, Linux, Android | No | Yes |
| Included in a bundle you may already own | No, separate purchase | Plan 2 included in Microsoft 365 E5 and E5 Security |
| Telemetry to SIEM | Yes | Yes, into the unified Defender portal and Sentinel |
| Content and web filtering | Yes, plus Jamf Safe Internet | Yes, web protection |
| Reported price | $3-$8 per Mac per month (reported, Vendr) | Bundled in E5, or licensed standalone |
If you want the wider security-tooling picture rather than just the endpoint agent, our roundup of AI tools for cybersecurity covers the detection and response layer that sits above both of these.
Running Both Together
A surprising number of Apple-heavy Microsoft shops land here, so it deserves honest costing rather than a footnote.
The architecture: Jamf Pro manages the Macs and iOS devices, Intune manages Windows and everything else, and the Jamf Device Compliance connector reports Mac compliance into Entra ID so Conditional Access gates Microsoft 365 access uniformly. You get Jamf's Apple depth and Microsoft's identity plumbing. You also pay for both, and the maths is not subtle.
| Fleet C, 200 people, 150 Windows, 50 Macs, 150 iPhones | Unit basis | Annual |
|---|---|---|
| Intune Plan 1 only, all platforms | 200 users at $8.00 | $19,200 |
| Jamf on 100 Apple devices only (reported band) | 100 devices at $8-$20+ | $9,600-$24,000+ |
| Both, Intune covering everything plus Jamf on Apple | 200 users plus 100 devices | $28,800-$43,200+ |
| Uplift for adding Jamf on top of Intune | +50% to +125% |
Whether that uplift is worth it comes down to one question: are you buying Jamf for capabilities Intune genuinely lacks, or for a reputation Intune has partly caught up to? On scripting, extension attributes and Smart Group workflows, the gap is real and documented. On day-one OS support, it has narrowed sharply. Answer that honestly before you sign for both.
Admin Skills and Operational Load
The skills each platform demands are different enough that the person who runs one is often not the person who can run the other.
| Dimension | Jamf | Intune |
|---|---|---|
| Core skillset | Mac admin, shell scripting, Apple MDM protocol, Jamf Pro's own policy model | Microsoft 365 and Entra administration, Windows CSPs, Intune policy model |
| Learning curve for a Windows-native IT team | Steep, unfamiliar object model | Low, the console is next to the ones they already use |
| Learning curve for a Mac-native admin | Low, this is the community's home turf | Moderate, Mac features are spread across separate policy types |
| Hiring pool | Smaller and more specialised, generally pricier | Very large, any Microsoft 365 admin has partial coverage |
| Community and tooling | Deep, long-established Mac admin community | Large, Microsoft-centric, plus a growing Mac-on-Intune community |
| Recommended onboarding | Jamf Premium Services engagement, per Jamf's pricing page | Self-serve or FastTrack, depending on licence |
| Number of consoles | One more to maintain | One, if it's your only platform |
Jamf's own pricing page recommends "an engagement with Jamf Premium Services" for "the best onboarding and implementation." Read that as a real, unpriced professional services line to fold into your first-year budget, not as boilerplate.
Migration Cost in Both Directions
Migrating between MDMs on Apple is harder than almost any other category of software, and both directions have a specific pain.
The core constraint is Apple's: a device can only be supervised by one MDM at a time. Microsoft's own Jamf integration documentation puts it plainly: "Any user with a macOS device that's already enrolled in either Jamf or Intune who is then targeted to enroll with the other MDM must unenroll their device and then re-enroll it with the new MDM before management of the device works properly."
| Migration | What breaks | What has to be rebuilt | Practical difficulty |
|---|---|---|---|
| Jamf to Intune | Extension attributes have no direct equivalent that can drive grouping; Smart Group logic doesn't port | Every custom inventory workflow, re-scoped as configuration profiles, compliance policies and scripts | High, and often reveals workflows nobody documented |
| Intune to Jamf | Windows estate needs a home, since Jamf doesn't manage it | Mac policies, Self Service catalogue, plus a parallel Windows solution | High, and rarely a full replacement |
| Either direction, on device | Supervision, FileVault escrow keys, certificates, VPN profiles, app assignments | Re-enrollment per device, with user involvement unless devices are in Apple Business Manager | Medium to high depending on ABM coverage |
| Old Jamf Conditional Access to Device Compliance | The legacy Conditional Access platform, unsupported since 31 January 2025 | Two Entra app registrations, two Smart Groups, one policy, Company Portal via Jamf App Catalog | Medium, well documented by Microsoft |
If your Macs are enrolled through Apple Business Manager, migration is unpleasant but tractable, because ADE lets you reassign the MDM server and re-enrol without touching every machine by hand. If they're not, budget for hands-on time per device. Our guide to switching SaaS vendors covers the contractual side, notice periods, data export and overlap windows, which is the part teams forget until renewal is thirty days out.
When Jamf Is the Right Call
- Your fleet is majority Apple and Mac depth is the actual job. Extension attributes feeding Smart Groups feeding scoped policies is a workflow Intune cannot reproduce, and Microsoft's own documented limits on custom attributes confirm it.
- You adopt new Apple capabilities early. Jamf's fourteen consecutive years of same-day support is the company's own claim, but the track record behind it is public and long.
- You run tvOS, visionOS or watchOS devices. Intune's supported platform reference does not list them.
- You have a Mac admin on staff, or the budget to hire one. Jamf rewards specialist expertise and punishes its absence.
- You are a school or university. Jamf School and Jamf's education pricing are a separate, purpose-built path that Intune answers only through Intune for Education, which is bundled into Microsoft 365 Education A3 and A5.
- You can accept a quote-only purchase. If your procurement process needs a list price before a call, Jamf will not give you one.
When Intune Is the Right Call
- Your fleet is mixed. Jamf does not manage Windows, Android, Linux or Chrome OS. That single fact resolves most mixed-fleet decisions on its own.
- You already pay for Microsoft 365 E3 or E5. Intune Plan 1 is included, and from July 2026 E3 also carries Plan 2, Remote Help and Advanced Analytics while E5 adds Endpoint Privilege Management, Cloud PKI and Enterprise Application Management. Those are add-ons you were previously quoted separately.
- Your device-to-user ratio is above 1.5. Per-user billing stops scaling with device count where per-device billing does not.
- Conditional Access is central to your security model. Intune is the native signal source; Jamf needs a connector, two app registrations and a Self Service registration flow.
- You need a published price to budget against. Every Intune figure in this article came off a Microsoft page, which is not something we can say about the other column.
- Your IT team is Microsoft-native. The hiring pool and the console familiarity are both dramatically larger.
One caution against the reflex answer. "We already own it" is only true if you are on the right plan, and an SMB on Business Standard is not. Moving up to Business Premium costs $22.00 per user per month against Standard's $14.00, a step of exactly $8.00, or $2,400 a year across 25 people. That figure should look familiar: it is precisely the standalone Intune Plan 1 rate. Microsoft charges the same $8.00 for Intune whether you bolt it onto a bundle or buy it alone. Compare the Copilot variants instead and the step is $23.50 to $32.00, or $8.50 per user per month.

Now put those two upgrades side by side, because the result is genuinely odd. Base Business Premium at $22.00 is cheaper than Business Standard with Copilot at $23.50. The plan that adds endpoint management across Windows, macOS, iOS and Android costs $1.50 per user per month less than the plan that only adds an AI assistant. That is not an argument against Copilot, it is an argument for pricing both upgrades properly instead of assuming device management is the expensive one. And for an all-Mac 25-person studio, Mosyle's free tier for up to 30 devices may cover the requirement at zero.
If Neither Fits
Plenty of teams read this far and realise the real requirement is smaller than Jamf and more Apple-native than Intune. The Apple MDM market has changed enough in the last year that the received wisdom about the alternatives is also out of date.

| Vendor | Published pricing | Basis | Platforms | Notable |
|---|---|---|---|---|
| Mosyle | Business FREE up to 30 devices; Business Premium $1.00; Fuse for macOS $3.00; Fuse for iOS, iPadOS and visionOS $1.50 | Per device, per month, billed annually, 30-licence minimum on paid plans | Apple only, watchOS and tvOS at no extra fee | The strongest genuinely free tier in Apple MDM now that Jamf publishes nothing |
| Iru (formerly Kandji) | None. "Pricing is based on the solutions your organization needs, as well as the number of users and devices" | Quote only | Apple plus Windows and Android since the rebrand | Kandji rebranded to Iru on 22 October 2025; every circulating per-device Kandji figure predates it |
| Hexnode | Pro $2.20 monthly / $1.98 annual; Enterprise $3.20 / $2.88; Ultimate $4.70 / $4.23; Ultra quote-only | Per device, per month, 15-device minimum, annual saves 10% | Cross-platform UEM | No free plan, 14-day trial, technician count rises with tier (2 to 5) |
| Addigy | Apple MDM "from $8.25 per Mac per month"; Security Suite "from $16 per Mac per month" | Per device, per month, monthly-versus-annual split not published | Apple, with iOS custom-quoted | Security Suite bundles SentinelOne EDR with 24/7 MDR and Entra plus Intune Conditional Access integration |
| JumpCloud | Device Management $9 annual / $11 monthly; SSO $11 / $13; Device and Identity Management $13 / $15 | Per user, per month | Cross-platform, identity-led | No free tier appears on the pricing page today, only a 30-day trial. Do not assume the old 10-user free plan still stands |
Three of those five publish real numbers, which puts them ahead of Jamf on budget predictability alone. Mosyle is the first call for a small all-Apple team. Hexnode is the first call if you want cross-platform coverage at a published per-device rate rather than a per-user one. Addigy suits teams where bundled EDR with managed detection matters more than console depth. Iru is a reasonable shortlist entry for Apple-first shops with some Windows, with the caveat that you land back in the same quote-only conversation you were trying to avoid.
If your evaluation is really about the service desk sitting behind the fleet rather than the fleet itself, that's a different purchase. Start with our how to choose ITSM software guide, then compare the two most common shortlists directly in Freshservice vs Jira Service Management, best Freshservice alternatives and best Jira Service Management alternatives. And if what you are actually replacing is Intune specifically, our best Intune alternatives roundup goes wider than this head-to-head does.
Decision Framework
| If you are... | Pick |
|---|---|
| An all-Apple team under 30 devices with a tight budget | Mosyle Business FREE, then Business Premium at $1.00 per device |
| An Apple-heavy team where scripted, event-driven Mac workflows are the job | Jamf |
| A mixed Windows and Mac fleet of any size | Intune |
| Already on Microsoft 365 E3 or E5 | Intune, you own it, and from July 2026 you own more of it |
| On Microsoft 365 Business Standard, considering the step to Business Premium | Price the $8.00 per user per month delta ($14.00 to $22.00) against a dedicated Apple MDM first |
| Over 300 people | Intune via E3 or E5. Business Premium caps at 300 users |
| Running a device-to-user ratio above 2.0 | Intune, per-user billing stops the bill scaling with device count |
| Managing tvOS, visionOS or watchOS at scale | Jamf |
| An Apple-heavy fleet inside a Microsoft identity estate | Both, Jamf for the Macs, Intune as the Entra compliance authority, at a 50% to 125% cost uplift |
| A school or university | Jamf School, or Intune for Education inside Microsoft 365 Education A3 or A5 |
| Required to have a list price before a vendor call | Intune, or Mosyle, Hexnode or Addigy. Jamf publishes nothing |
The verdict. Jamf remains the better Apple management product, and the depth gap in scripting, extension attributes and Smart Group workflows is real and documented rather than marketing. But two things have changed the calculus in 2026. Intune now commits to day-zero Apple OS support, which erodes Jamf's most-quoted differentiator, and Microsoft moved a stack of previously paid Intune add-ons into E3 and E5 in July 2026, improving the value of a licence most enterprises already hold. Against that, Jamf has stopped publishing prices entirely and went private in January. For a Mac-only shop with real configuration complexity, Jamf still earns its quote. For everyone else, Intune is the default, and the burden of proof has shifted onto Jamf to justify the premium you cannot see before you call.

What to Do Next
- Calculate your device-to-user ratio before you calculate anything else. Total managed devices divided by total people. Below 1.2, compare rates directly. Above 2.0, per-user billing is structurally cheaper and no negotiated Jamf discount is likely to close the gap.
- Check what your Microsoft licence already includes. If you're on E3 or E5, you gained Intune capabilities in July 2026 that you may still be paying for separately as add-ons. That audit is free and can cancel line items today.
- Get the Jamf quote early, per device and per year. Since nothing is published, the quote is the only real number. Ask specifically whether Jamf Connect and Jamf Protect are included or separate, since the reported bands suggest they add meaningfully to the per-Mac cost.
- Trial both against your hardest workflow, not your easiest. Pick the automation you'd genuinely miss and build it in each. If it's keyed off custom inventory data, you'll find Intune's limits in an afternoon. If it isn't, you may find you don't need Jamf.
- Pressure-test the compliance angle before you shortlist. Our security and compliance review guide is a workable checklist for the questions procurement will ask six weeks later.
Frequently Asked Questions about Jamf vs Intune
How much does Jamf cost per device?
Jamf does not publish a per-device price. Its pricing page lists ten products and no dollar figures, closing with a line directing buyers to contact a Jamf representative or an authorised reseller for a quote in their local currency. The only published price is on the Jamf Now product page, which offers management of up to three devices for free. Procurement platform Vendr reports observed Jamf Pro rates of $8 to $20 or more per device per month depending on volume, but that is buyer-side contract data, not a list price.
Is the $4.17 per device Jamf Pro price still accurate?
It is not on any current Jamf page, so it cannot be verified as a live price. Competing comparison articles repeat it widely, along with $6.25, $8.25, $12.50 and $13.33, none of them traceable to a Jamf URL that exists today. Treat every circulating Jamf figure, including the ones in this article, as reported rather than published, and get a quote.
How much does Microsoft Intune cost?
Microsoft Intune Plan 1 is $8.00 per user per month, paid yearly, and can be bought standalone. Plan 2 is $4.00 per user per month and requires Plan 1. The Intune Suite is $10.00 per user per month and also requires Plan 1. Plan 1 is included in Microsoft 365 E3, E5 and EMS E3 and E5, and in Microsoft 365 Business Premium at $22.00 per user per month paid yearly ($26.40 on monthly billing, $32.00 for the Copilot variant). Business Premium is the cheapest Microsoft 365 business plan that includes Intune, and it caps at 300 users.
Does Jamf manage Windows devices?
No. Jamf is an Apple-only platform covering macOS, iOS, iPadOS, tvOS, visionOS and watchOS, and Jamf Protect covers macOS, iOS and visionOS. If you have any Windows devices, Jamf cannot be your only endpoint management platform. Intune supports Windows, macOS, iOS/iPadOS, Android, Linux and Chrome OS.
Why does per-user versus per-device billing matter so much?
Because it changes the answer as your fleet shape changes. Intune licences a person and Microsoft's enrollment documentation allows a device limit of one to fifteen devices per user, so a designer with a MacBook, an iPhone and an iPad is one Intune seat. Jamf licences each device, so the same person is three Jamf units. At a device-to-user ratio of 1.0 the two models compare directly. At 2.0, Jamf's bill doubles while Intune's does not move.
Can you run Jamf and Intune together?
Yes, and many Apple-heavy Microsoft shops do. Jamf manages the Macs, Intune manages everything else, and the Jamf Device Compliance connector reports Mac compliance into Microsoft Entra ID so Conditional Access works uniformly. Note that Jamf's older Conditional Access integration was deprecated on 31 January 2025 and no longer accepts new configurations, so new deployments must use the Device Compliance path. Jamf-managed Macs do not appear in the Intune device list, and running both typically adds 50% to 125% to the annual bill.
Does Intune support new Apple operating systems on release day?
Yes, as of the OS 26 wave. Microsoft's Intune Customer Success team published day zero support for iOS/iPadOS and macOS 26, with the settings catalog updated for both declarative device management and classic MDM settings. Jamf still claims a longer record, fourteen consecutive years of same-day support for Apple's fall releases, and generally surfaces brand-new niche capabilities sooner. The blanket claim that Intune does not support new Apple releases on day one is no longer accurate.
What are the best alternatives to Jamf and Intune?
Mosyle is the strongest option for small Apple-only teams, with a free tier up to 30 devices and Business Premium at $1.00 per device per month on a 30-licence minimum. Hexnode publishes cross-platform per-device pricing from $1.98 per device per month on annual billing with a 15-device minimum. Addigy starts at $8.25 per Mac per month with a Security Suite bundling SentinelOne EDR from $16. Iru, formerly Kandji until its October 2025 rebrand, now covers Windows as well as Apple but publishes no pricing. JumpCloud takes an identity-led per-user approach from $9 per user per month on annual billing.
Related Resources:
- Best SaaS Management Software in 2026
- Best Intune Alternatives in 2026
- Best Freshservice Alternatives in 2026
- Best Jira Service Management Alternatives in 2026
- Freshservice vs Jira Service Management
- How to Choose ITSM Software
- SaaS Vendor Evaluation Scorecard
- TCO Modeling for SaaS
- Switching SaaS Vendors
- Security and Compliance Review
- Best AI Tools for Cybersecurity in 2026

Principal Product Marketing Strategist
On this page
- TL;DR
- Key Facts
- The Pricing Asymmetry Nobody Puts in the Comparison Table
- Per User or Per Device: The Unit Mismatch That Breaks Most Comparisons
- What Three Real Fleets Actually Cost
- Same-Day Apple OS Support
- macOS and iOS Configuration Depth
- Windows, Android and Linux Coverage
- Zero-Touch Enrollment
- Identity and Conditional Access
- Patching and App Lifecycle
- Security Posture: Jamf Protect vs Defender for Endpoint
- Running Both Together
- Admin Skills and Operational Load
- Migration Cost in Both Directions
- When Jamf Is the Right Call
- When Intune Is the Right Call
- If Neither Fits
- Decision Framework
- What to Do Next