Best MDM for Mac: A Practical Guide for Teams Choosing Apple Device Management

Independent guide to the best MDM for Mac in 2026. Seven platforms on real published pricing, what changed when Apple Business replaced Apple Business Manager, and the two questions that decide it.

Michael Rodriguez Michael Rodriguez • • 26 min read

TL;DR

  • What this decides: which platform configures, secures and reports on your Macs, and how much of that work a person has to do by hand.
  • When you don't need one: under about ten Macs with no compliance obligation. Apple Business now includes free built-in management, and for a simple fleet that is genuinely enough.
  • What changed in 2026: Apple retired Apple Business Manager on 14 April and replaced it with Apple Business, which carries Apple's first built-in MDM at no cost. The point where paying becomes necessary has moved.
  • Published prices exist now: Jamf is $12.50 per Mac per month, Addigy starts at $8.25, Hexnode starts at $2.20. Mosyle and Iru still quote.
  • The decision rule: count your Macs as a share of the fleet, then name the person who will operate the console on a Tuesday in eight months.
  • The outcome: one console somebody actually owns, rather than a licence renewing against capability nobody was staffed to use.

The Shortlist That Does Not Narrow

A team of ninety has sixty Macs and a new SOC 2 commitment. The IT lead opens five vendor sites in five tabs. Every one of them says centralised management, zero-touch deployment, automated compliance and endpoint security. Four hours later the tabs are still open and the shortlist is still five.

The problem is not research. It is that at this level of description the products are identical, and they are identical because they are all built against the same Apple frameworks. Configuration profiles, declarative device management, automated enrollment, volume app purchasing: these are Apple's, not any vendor's. A platform exposes them. It does not invent them.

So the differences that matter are not in the feature list. They are in how much the platform assumes about you. Some are built for an administrator who will write scripts and read Apple's deployment documentation. Others are built to be usable by somebody whose actual job is something else. Both approaches are legitimate and they fail in opposite directions.

That is the question to answer before opening a single vendor site. Not what can this do, but how much of this will somebody here actually operate.

When You Don't Need a Dedicated Mac MDM

When Apple's own management covers it

This changed in April 2026 and a lot of advice has not caught up. Apple retired Apple Business Manager, Apple Business Essentials and Apple Business Connect on 14 April and replaced all three with Apple Business, free in more than 200 countries, and it includes Apple's first built-in mobile device management. Blueprints handle employee groups, device settings, security and apps.

For ten Macs in one office with no auditor asking questions, that is a real answer rather than a stepping stone. Try it before paying for anything. The worst case is that you learn what your actual requirements are using a free tool.

Free Weekly Briefing Stay ahead of what's changing in HR and people ops.

Join 4,200+ leaders getting practical insights every week — no fluff, just signal.

Join Free →

When friction starts showing

The first signal is usually repetition. Somebody is doing the same setup by hand for the fourth time this month, or a question like "which of our Macs are encrypted" takes an afternoon and produces a number nobody fully trusts.

The second is onboarding time. When a new starter waits two days for a machine because configuration is manual, the gap has stopped being an inconvenience and become a recurring cost measured in salary.

When it becomes a liability

The moment somebody outside IT needs device evidence on a schedule, the tooling question stops being a preference. SOC 2, ISO 27001 and most customer security questionnaires want to know which devices hold company data, who has them, and whether disk encryption and patch levels are enforced rather than hoped for. "We think so" is not an answer you can submit.

The edge case that forces it

Rapid distributed growth. Going from one office to people in nine countries in a year will expose whichever part of your process was being held together by one person's memory. With Macs, that part is almost always enrollment, because a machine that was never enrolled properly cannot be fixed remotely later.

Five Questions Mac Admins Ask at 11pm

"Why can't I just add this Mac to the system?" Because automated enrollment is decided at purchase, not afterwards. A Mac bought retail or on a manager's card to solve an emergency cannot be retrofitted into automated enrollment. It can be enrolled by hand, with a profile the user could remove.

"Who is actually going to run this?" The question that predicts success better than any feature comparison. Jamf rewards somebody fluent in Apple deployment and punishes somebody who is not. Mosyle and Iru are built to need less of that person. These are different products for different staffing realities.

"What happens when macOS ships a major release?" Apple ships one every autumn, and new management capabilities arrive in the Apple specialists faster than in cross-platform suites. If your organisation updates promptly, that lag is a live operational issue each September.

"How do I prove encryption is on across the fleet?" Every platform here can answer it. What differs is whether the answer is one screen or an export plus a spreadsheet. Ask to see that specific report during a trial, with your own devices in it.

"What do I do about the Macs nobody enrolled?" Find out how many there are before you choose a platform, because that number changes which migration you are signing up for and no vendor can fix a machine they have never seen.

The pattern across those five is worth naming. Four of them are answered by information you already hold and have never written down, and only one of them is answered by a vendor. That ratio is normal in this category and it is why the research phase so often feels unproductive: the questions that decide the outcome are internal, and the ones vendors are eager to answer are not the ones holding you up.

There is a sixth question that only surfaces later, usually at renewal. "Can somebody else operate this if the person who set it up leaves?" Device management concentrates in one head more reliably than almost any other IT function, and Apple deployment knowledge is specialised enough that the honest answer is frequently no. Ask it early, because it changes which platform is the right risk rather than which is the better product.

Apple Business Comes First, and It Is Free

Every platform below depends on it, and it is the step teams consistently underestimate.

One naming change first, because it is recent enough to cause confusion. Apple retired Apple Business Manager, Apple Business Essentials and Apple Business Connect on 14 April 2026 and replaced all three with a single free platform called Apple Business. Documentation and vendor onboarding guides that still say Apple Business Manager mean this.

What it does has not changed. Apple Business is what enables automated device enrollment, where a Mac enrolls itself during first setup rather than relying on somebody installing a profile they could decline, and it handles volume app purchasing and Managed Apple Accounts.

Setting it up means verifying a domain you own, deciding how it federates with your identity provider, and linking your hardware resellers. None of that is difficult. All of it waits on somebody else, which is why it takes longer than the hour it looks like.

The federation decision deserves more than a quick click. Federating means people sign in to Apple services with their work account, which is normally what you want, but it also captures existing personal Apple Accounts that happen to use a company email address. Those users get prompted to change theirs, and if nobody warned them you get a wave of tickets from people who have used that address for years. That is not a reason to avoid federation. It is a reason to announce it first, which costs one email.

And the purchasing rule applies to every platform equally. Devices must be bought through Apple or an enrolled reseller to appear in automated enrollment. Audit how your organisation actually buys hardware before choosing anything, because the rule is procedural rather than technical. The emergency purchase is the usual culprit: a laptop dies, a manager buys a replacement locally to keep somebody working, and that machine sits permanently outside automated enrollment. One is an annoyance. A pattern of them creates a second tier in your fleet your enrollment numbers cannot explain.

The Three Categories of Mac Management

Apple specialists

Built for Apple and nothing else. Jamf, Mosyle, Iru and Addigy. They support new macOS capabilities fastest, go deepest on Apple-specific controls, and their documentation assumes you are managing Apple hardware rather than treating it as one platform among several.

When it is right: Apple is the majority of your fleet, or the minority that matters most.

When it fails: you also have three hundred Windows machines and now run two consoles with two policy sets nobody reconciles.

Cross-platform suites

One console for Apple, Windows and Android. Microsoft Intune and Hexnode are the common choices. The Mac support is real and visibly second: core management is there, timing and depth lag.

When it is right: genuinely mixed fleets, and especially organisations already paying for Microsoft 365, where Intune Plan 1 capability is included with E3 and E5 and the marginal cost of managing Macs with it is nothing.

When it fails: Apple-majority fleets, where you accept the weaker tool on most of your estate to avoid a licence you would gladly pay for.

Apple's own built-in management

Apple Business, free, since April 2026. Blueprints, groups, settings, apps.

When it is right: small fleets, simple requirements, no compliance obligation, no appetite for a procurement cycle.

When it fails: policy depth, scripting, third-party patch management and detailed compliance reporting. It is a floor that rose, not a ceiling that moved.

Category Platforms Right when Fails when
Apple specialists Jamf, Mosyle, Iru, Addigy Apple is the majority, or the minority that matters most You also run a large Windows estate
Cross-platform suites Microsoft Intune, Hexnode Genuinely mixed fleets, or Microsoft already paid for Apple is most of your estate
Apple's built-in management Apple Business Small fleet, simple needs, no audit obligation You need depth, scripting or patch management

The categories matter more than the individual products, because choosing the wrong category is expensive and choosing the wrong product inside the right category is merely annoying. A platform you outgrow can be replaced at renewal. A category mismatch means running two consoles or accepting a compromise on most of your devices, and neither is fixed by switching vendor within the same row.

How to Choose: Five Questions Before You Talk to Any Vendor

Count the Macs as a percentage. Not the absolute number, the share. Eighty per cent Apple and twenty per cent Apple point at different categories, and the number takes an afternoon to establish.

Name the administrator. A specific person. Then ask what they already know. Apple deployment knowledge is specialised enough that the honest answer is often nobody, and that answer points away from depth and towards pre-built automation.

Get the compliance requirement in writing. From whoever owns it, security or compliance rather than IT. Decisions made on an assumed requirement over-buy, and the person who owns the obligation can usually say in one sentence what evidence they must produce and to whom.

Establish what you already pay for. Organisations buy Apple management while holding Microsoft 365 E3 licences that include Intune capability, because nobody checked. That is a real recurring cost paid for nothing.

Ask what broke last quarter. If a machine was misconfigured, unpatched or missing encryption, this is the right comparison. If a laptop never came back or an audit found hardware nobody had recorded, it is not, and no MDM on this list addresses it.

Seven Platforms Worth Knowing

Pricing below is what each vendor published on its own site, checked on 3 October 2026. Where a vendor does not publish, this says so rather than estimating.

Apple Business

Best for: small Apple fleets, and anybody who should establish their requirements before buying.

Why teams choose it: free, from Apple, and already required for enrollment regardless of what else you run. Blueprints cover groups, settings, security and apps without a licence conversation.

Where it struggles: no scripting layer, no third-party patch management, and compliance reporting that stops well short of what an auditor-facing process wants. Depth is the trade for the price.

Jamf

Best for: Apple-primary fleets with an administrator who will use the depth.

Why teams choose it: the deepest Apple management available and the largest body of worked knowledge in the category, which matters more than it sounds. A large share of real configuration work is solved by finding somebody who hit the same problem and published what they did.

Where it struggles: it assumes an administrator. Teams expecting to configure it in an afternoon are consistently surprised, and the capability goes unused without that person.

Pricing: Jamf for Mac is $12.50 per macOS device per month, billed annually, with a 25-device minimum, and bundles Jamf Pro with Jamf Connect and Jamf Protect rather than selling management alone. Jamf for Mobile is $5.75 per mobile device per month. Jamf Now, aimed at smaller teams, starts at $4 per device per month.

Mosyle

Best for: Apple-only teams that want capability without an Apple specialist on staff.

Why teams choose it: built exclusively for Apple, with automation that works out of the box rather than requiring assembly, and a free tier that is genuinely usable for small fleets rather than a crippled trial.

Where it struggles: Apple only, so a mixed fleet means a second tool. Pricing is not published in a form that can be verified from outside, so budgeting means a conversation.

Iru (formerly Kandji)

Best for: Apple fleets wanting automated remediation rather than scripts they maintain themselves.

Why teams choose it: pre-built automation that checks a device against a desired state and fixes drift without an administrator writing the logic. For teams without deep Apple scripting skills that is the main argument.

Where it struggles: the brand changed. Kandji rebranded to Iru on 22 October 2025 and kandji.io now redirects to iru.com, so older comparisons, internal notes and procurement records may name a company that no longer exists under that name. Pricing is not published.

Addigy

Best for: managed service providers and internal teams that operate like one.

Why teams choose it: built around managing many separate environments from one place, with monitoring and scripting aimed at people who do this for a living.

Where it struggles: the multi-tenant design is overhead if you have exactly one tenant, and it is the most expensive published entry on this list.

Pricing: plans start at $8.25 per Mac per month with no multi-year contract required. The Security Suite starts at $16 per Mac per month. Lower per-device rates are available for MSPs.

Microsoft Intune

Best for: Microsoft-centric organisations where Macs are a minority.

Why teams choose it: you very likely already own it. Intune Plan 1 capability is included with Microsoft 365 E3 and E5, so managing Macs with it has a marginal cost of nothing, and device compliance ties natively into conditional access through Entra ID.

Where it struggles: Mac support is capable and visibly second. New macOS capabilities arrive later than in the Apple specialists, some Apple-specific controls are shallower, and the enormous Intune community is overwhelmingly focused on Windows, so an unusual macOS question has far fewer existing answers.

Hexnode

Best for: mixed fleets that want transparent per-device pricing.

Why teams choose it: Apple, Windows and Android from one console, and it publishes its rate card, which makes budgeting possible without a sales cycle. For some evenly split fleets a single adequate tool beats two excellent ones with a reconciliation problem between them.

Where it struggles: second-best at Apple by design. If Macs are the majority you are accepting that compromise on most of your estate.

Pricing: on annual billing, $2.20 per device per month for Pro, $3.20 for Enterprise, $4.70 for Ultimate and $5.40 for Ultra. Monthly billing is $2.40, $3.60, $5.20 and $6.00 respectively.

What Each One Published

Platform Published price Unit Notes
Apple Business Free n/a Built-in MDM since 14 April 2026
Hexnode $2.20 to $5.40 per device, per month Annual billing, four tiers
Jamf Now From $4.00 per device, per month Smaller-team product
Addigy From $8.25 per Mac, per month Security Suite from $16.00
Jamf for Mac $12.50 per macOS device, per month Annual, 25-device minimum, bundle
Mosyle Not published n/a Free tier exists, paid tiers quote
Iru Not published n/a Formerly Kandji
Microsoft Intune Included per user Plan 1 capability with M365 E3 and E5

Two cautions on reading that table. The Jamf figure is a bundle of Jamf Pro, Jamf Connect and Jamf Protect, so it is not comparable to a management-only licence from somebody else. And Intune being included is a sunk-cost observation rather than a statement that it is cheaper, which is a different and weaker argument than it first appears.

Price is also the wrong column to sort on first, because the spread between the cheapest and the most expensive entry here is smaller than the cost of one administrator spending a day a week fighting the wrong tool. Sort on fit, then check that the price is survivable.

Platform Apple depth Manages Windows Assumes an Apple admin Price published
Apple Business Basic No No Free
Jamf Deepest No Yes Yes
Mosyle Deep No Less so No
Iru Deep No Less so No
Addigy Deep No Yes Yes
Microsoft Intune Second Yes Microsoft skills instead Included with E3 and E5
Hexnode Second Yes Moderate Yes

The fourth column is the one worth staring at. It is not a quality judgement, and a platform that assumes an administrator is not worse than one that does not. It is a statement about what the product expects you to bring, and it is the column that most reliably predicts whether a purchase gets used.

The Decision Table

Situation Scale Setup Primary Pain Recommended Starting Point
All Apple, no compliance obligation Under 10 One office Manual setup repetition Apple Business, free
All Apple, no Apple admin 10 to 100 Distributed Nobody owns the tooling Mosyle or Iru
Apple-primary, audit obligation 50 to 500 Any Producing device evidence Jamf
Macs a minority of a Microsoft estate 100 plus Any Already paying for Intune Microsoft Intune
Genuinely mixed, roughly even split 100 to 500 Any Two consoles, one truth Hexnode
Many separate client environments Any Multi-tenant Managing tenants, not devices Addigy
Devices not coming back at offboarding Any Remote Physical recovery, not configuration Not an MDM problem

Most organisations sit in the first four rows, and the Mac percentage plus the administrator question tells you which. The third row is the one most often mis-assigned, because teams with an Apple-primary fleet and no Apple administrator reach for Jamf since it is the name they know. Choosing Jamf and then not staffing it produces the worst outcome available: enterprise cost, basic configuration.

Where Teams Get This Wrong

Buying depth nobody will use. The most expensive mistake in this category. An organisation buys for capability, nobody has time to learn it, and six months later it runs a handful of basic policies any cheaper platform would have handled. The comparison that justified the purchase was never wrong. It was simply about capability nobody was staffed to use.

Paying twice. Holding Microsoft 365 E3 and buying Apple management without checking what the licence already includes. Check before you shortlist.

Treating the free option as a toy. Apple Business changed in April 2026 and a lot of advice predates it. For a simple fleet, starting free and discovering your real requirements costs nothing and is better research than any vendor call.

Choosing before counting. The Mac percentage settles more than any feature grid, and nobody establishes it because it feels too obvious to check.

Assuming an MDM fixes asset management. It does not, and this is the most common category error. More below.

Announcing a migration before writing the user communication. The technical work is straightforward. The part that goes wrong is social, and it is entirely preventable by writing the message first.

Evaluating on a spare machine. A laptop with no real user, no real data and nobody who will complain tells you almost nothing about daily operation. Every platform here looks competent on a clean device. What separates them is what happens when a policy lands on somebody mid-task.

Shortlisting from an article that was not fact-checked recently. This category moves faster than its published advice. Kandji became Iru in October 2025, Apple Business Manager was retired in April 2026, and Jamf began publishing list pricing having previously declined to. A roundup carrying any of those three as current is telling you how recently somebody checked, which is a reasonable way to decide how much of the rest to trust.

What an MDM Will Never Tell You

An MDM knows about devices it manages. That sounds complete until you need the other list.

It cannot tell you about a Mac that was never enrolled, because it has never seen it. It cannot tell you where a laptop physically is, only where it last checked in from. It cannot tell you whether the machine assigned to somebody who left in March came back, only that it stopped reporting. And it cannot tell you what you own, which is the question an auditor actually asks.

That is an asset management gap rather than an MDM shortcoming, and the fix is a register alongside the MDM rather than a better MDM. Platforms built for that side of the problem, such as RemoAsset, handle procurement, delivery and physical retrieval, with MDM enrollment happening on delivery. Neither category replaces the other. RemoAsset is not an MDM and does not try to be one, and a team whose real problem is device recovery will deploy any platform on this list perfectly and find the problem untouched.

The diagnostic is one question. Ask what broke last quarter. If a machine was misconfigured, unpatched or missing encryption, this comparison is the right one. If a laptop never came back, or an audit turned up hardware nobody had recorded, the budget should go elsewhere.

What to Establish Before You Commit

Your Mac percentage, written down. The single most decisive number and the one least often established.

The named administrator, and what they already know. If the answer is that nobody knows Apple deployment well, that is useful information rather than a dead end. It points away from depth and towards pre-built automation, and it means the budget conversation should include training or a managed service rather than only licences.

The compliance requirement, from its owner. In writing, in one sentence.

How your organisation actually buys hardware. Including the emergency purchases nobody logs, because that procedural gap defeats every platform here equally.

The count of unenrolled Macs. Before you choose, not after.

What your existing licences already include. Specifically Microsoft 365, specifically Intune.

None of those six requires a vendor conversation, and that is the point. They are all answerable from inside your own organisation in about a day, and together they eliminate most of the shortlist before anybody books a call. The reason teams skip them is that they feel like preparation rather than progress, and a demo feels like progress. The demo is the part that can wait.

If you can only do one, do the Mac percentage. It is a single number, it takes an afternoon, and it rules out more options than the other five combined.

What Getting This Wrong Costs

The first cost is a licence renewing against unused capability. It is visible, annoying and the easiest to recover from, because you can change platform at renewal.

The second is the migration you will eventually run anyway, and it is larger than vendors suggest. Every device must be unenrolled from the old platform and enrolled into the new one. In an office that is a trolley and an afternoon. Across a distributed fleet it means asking each person to act on their own laptop, the stragglers take weeks, and you run two consoles until the last one finishes.

The third shows up at the audit, and it is the one that costs something other than money. A fleet where enrollment was never complete produces compliance evidence with a hole in it, and the hole is discovered by somebody who is not on your side. That is not a tooling failure. It is the accumulation of individual exceptions, each reasonable at the time.

A useful tactic that makes the second cost much smaller: migrate new hires first. Every machine issued after the switchover date arrives on the new platform with no user involvement at all, and you work backwards through the existing fleet at whatever pace people cooperate. The tail gets longer and the disruption gets considerably smaller, which is usually the right trade.

What a Two-Week Trial Should Actually Test

Most trials establish that the product works, which was never in doubt. A useful one establishes whether your team can operate it, which is a different question and the one that decides the next three years.

Enroll a device belonging to somebody who will complain. Not a spare. A real machine with real data and a user who will tell you when something is annoying. The complaint is the signal you are paying for.

Push a policy that the user will notice, then try to undo it. A screen lock timeout, a required update, a restricted setting. You are testing two things at once: whether enforcement actually holds, and how much support load it generates. A policy nobody notices has proved nothing.

Produce the compliance report you will actually be asked for. Not a sample. The specific one your auditor or your largest customer's security questionnaire wants, with your own devices in it. This is where platforms separate most visibly, and it is almost never part of a vendor demo because it is unglamorous.

Break something deliberately. Fail a device against a policy and watch whether the platform notices, reports it and remediates it, or simply records it and waits for a human. The gap between flagging and fixing is the main practical difference between the Apple specialists.

Have the administrator do all of the above without help. No vendor engineer on a call, no solutions architect sharing a screen. If your actual administrator cannot get a policy out without an hour of documentation, that is the finding, and it will not improve after purchase.

Time the enrollment of one device end to end. From unboxing to usable, with nobody intervening. That number multiplied by your hiring rate is the recurring cost you are trying to remove.

Two weeks is enough for all of it. What it is not enough for is the thing teams actually spend trials on, which is exploring features nobody has committed to using.

When You Are Ready to Decide

Establish the Mac percentage, name the administrator, and get the compliance requirement in one sentence from whoever owns it. Those three answers eliminate most of this list before any demo.

Then trial the leading candidate on real devices rather than spares. Enroll a machine belonging to somebody who will complain, push a policy they will notice, and try to undo it. What separates these products in daily use is how that loop feels, and no comparison grid captures it.

And give the trial to the person who will own it, not to whoever is most curious. The useful signal is whether your actual administrator can get a policy out without reading documentation for an hour, because that is what the next three years look like.

If your fleet is small and your requirements are simple, start with Apple Business. It is free, you need it anyway, and the worst case is that you learn precisely what you are missing.


Frequently Asked Questions

What is the best MDM for Mac?

There is no single answer, and the honest version is that the question has two inputs rather than one. Count your Macs as a percentage of the total fleet, then name the person who will operate the console day to day. An Apple-majority fleet with a capable Apple administrator points at Jamf, an Apple fleet without that person points at Mosyle or Iru, Macs as a minority inside a Microsoft estate points at Intune because you almost certainly already own it, and a genuinely even split points at a cross-platform tool like Hexnode. If you have fewer than about ten Macs and no compliance obligation, start with Apple Business, which has been free since April 2026 and includes built-in management.

Does Apple have its own free MDM?

Yes, and this is recent enough that a lot of published advice has not caught up. Apple retired Apple Business Manager, Apple Business Essentials and Apple Business Connect on 14 April 2026 and replaced all three with a single free platform called Apple Business, available in more than 200 countries and regions, which includes Apple's first built-in mobile device management along with Blueprints for configuring employee groups, device settings, security and apps. It does not match the paid platforms on policy depth, scripting or third-party patch management, but it moves the point at which paying becomes necessary, and for a small fleet with straightforward requirements it is a genuine answer rather than a stepping stone.

How much does Jamf cost for Mac?

Jamf publishes list pricing, which it did not always do, though not for Jamf Pro on its own. The Jamf for Mac plan is $12.50 per macOS device per month, billed annually, with a 25-device minimum, and that figure bundles Jamf Pro together with Jamf Connect and Jamf Protect rather than pricing the management product separately. Jamf for Mobile is $5.75 per mobile device per month on the same terms, and Jamf Now, aimed at smaller teams, starts at $4 per device per month. Because those are list figures for bundles, a standalone quote still comes from a sales conversation, so ask for the number at your projected device count as well as today's.

Is Intune good enough for Macs?

For most organisations where Macs are a minority, yes, and the licence argument is strong. Core management is there: enrollment through Apple Business, configuration profiles, compliance policies, FileVault enforcement and application deployment, and device compliance ties natively into conditional access. What lags is timing and depth, because new macOS capabilities arrive later than they do in the Apple specialists and some Apple-specific controls are shallower, which matters most each autumn when Apple ships a major release. At eighty per cent Windows that compromise affects a minority of devices and the saving is real. At sixty per cent Apple it is a trap.

What happened to Kandji?

Kandji rebranded to Iru on 22 October 2025, and kandji.io now redirects to iru.com. The product and its approach are unchanged, so comparisons of its capabilities still apply, but the name does not, which matters more than it sounds for two practical reasons. Older roundups, internal runbooks and procurement records will name a company that no longer exists under that name, and any shortlist or vendor comparison you inherited from before late 2025 should be treated as dated on this point. If you are reading a 2026 article that still ranks Kandji as a current brand, that is a reasonable signal about how recently its facts were checked.

Do I need Apple Business if I already have an MDM?

Yes, and no third-party platform avoids it, including Microsoft's. Apple Business is what enables automated device enrollment, where a Mac enrolls itself during first setup rather than depending on somebody installing a configuration profile they could later remove, and it also handles volume app purchasing and Managed Apple Accounts. Without it you are relying on manual enrollment that a user can undo, which undermines the compliance evidence the platform exists to produce. Set it up before you shortlist platforms rather than after you choose one, because verifying a domain and settling the identity federation question both involve waiting on other people and routinely add a week.

Can I manage Macs bought from a retail store?

Not through automated enrollment, and this catches people out because it is procedural rather than technical. Devices must be bought through Apple or an enrolled reseller to appear in automated device enrollment, and a Mac bought at retail or on a manager's company card cannot be retrofitted into it later. You can still enroll that machine by hand, but the enrollment is one a user could remove, which means it sits in a different and weaker category than the rest of your fleet. The usual culprit is the emergency purchase when a laptop dies, and a pattern of those creates a second tier your enrollment numbers cannot explain.

Will an MDM tell me where my laptops are?

No, and expecting it to is the most common category error in this space. An MDM knows about devices it manages and reports where they last checked in from, which is not the same as knowing where a machine physically is, whether the laptop belonging to somebody who left in March came back, or what hardware you own but never enrolled. That is an asset management gap rather than a shortcoming of any platform here, and the fix is a register alongside the MDM rather than a better MDM. Ask what broke last quarter: a misconfigured or unpatched machine is an MDM problem, and a laptop that never came back is not.

Share on X Share on LinkedIn

What to do next?

Explore More Articles

Dig deeper into HR Ops strategy, tools, and workflows built for real teams.

Browse the blog →
Join the HROpsLab Community

Connect with People Ops practitioners sharing real workflows, tools, and challenges.

Join now →