TL;DR
- The awkward fact first: if you hold Microsoft 365 E3 or E5, you already own Intune. Leaving means paying for something you have, so the reason needs to be good.
- The reason that is usually good enough: Apple. Intune manages Macs capably and visibly second, and on an Apple-majority fleet that compromise lands on most of your estate.
- The reason that usually is not: complexity. Intune is demanding, but so is every platform at that scale, and a simpler tool with fewer capabilities is not automatically the fix.
- What the alternatives publish: Hexnode from $2.20 per device, Scalefusion from $2, NinjaOne from $1.50 at volume, Jamf at $12.50 per Mac. Mosyle and Iru quote.
- The free floor moved: Apple Business replaced Apple Business Manager in April 2026 and includes Apple's own built-in MDM at no cost.
- The decision rule: work out whether you are solving an Apple problem, a complexity problem or a licensing problem. Only the first reliably points away from Intune.
The Comparison That Starts From the Wrong Place
An IT lead with 240 Windows machines and 60 Macs is told the Mac experience is unacceptable. The design team cannot install what they need without a ticket, software updates lag, and a configuration somebody wanted took a fortnight and a support case.
So the search begins for an Intune alternative, and within an hour the shortlist is full of Apple specialists that do not manage Windows at all.
That is the structural problem with this particular comparison. Intune is doing one job badly and three jobs adequately, and most of its alternatives are built to do the one job brilliantly and the other three not at all. Replacing it wholesale to fix the Mac complaint means accepting a new gap somewhere else, usually on the 240 machines nobody was complaining about.
Best tools for Device Management
Which means the first question is not which platform is better. It is whether you are replacing Intune or supplementing it, because those lead to completely different answers and only one of them involves giving up a licence you already pay for.
The second question is harder and worth asking before any demo: is the Mac experience bad because Intune is weak on Apple, or because nobody has configured the Apple side properly? Those look identical from the outside and the fix for one is not the fix for the other. Apple management inside Intune is its own learning curve rather than a checkbox, and owning the licence does not mean anybody has climbed it.
When You Should Not Replace Intune
When the licence is already paid
This is the strongest argument for staying and it is purely financial. Intune Plan 1 capability is included with Microsoft 365 E3 and E5. If you hold those licences, the marginal cost of managing devices with Intune is nothing, and every alternative on this page is a new line item.
That does not make Intune the right tool. It does mean the alternative has to be better by enough to justify paying twice, and plenty of teams discover the margin is thinner than the frustration suggested.
When Macs are a genuine minority
At eighty per cent Windows, Intune's Apple compromises affect a fifth of your devices and the saving is real. Running a second platform for that fifth means two consoles, two policy sets, two compliance reports nobody reconciles, and a standing requirement that somebody understands both. For a small Mac population that overhead usually exceeds the irritation it removes.
When conditional access is a requirement
Intune ties device compliance into conditional access natively through Entra ID, so a non-compliant machine can be blocked from resources without an integration in between. Alternatives achieve this through connectors, which work and which add a dependency, a support boundary and an item in a vendor risk assessment. None of that makes them wrong. All of it belongs in the comparison.
When the real problem is that nobody configured it
The most common misdiagnosis in this category. An Intune tenant set up for Windows and then pointed at Macs without anybody learning Apple deployment will produce exactly the complaints above, and so will any replacement configured the same way. Before switching, establish whether somebody has actually built the Apple side or whether it was assumed to follow automatically.
Five Questions Teams Ask Before Switching
"Are we replacing Intune or adding to it?" The question that determines everything else. Replacing means finding one tool that covers Windows, Apple and mobile. Adding means keeping Intune for Windows and putting an Apple specialist alongside it, deliberately rather than accidentally.
"What exactly is bad about the Mac experience?" Get specifics rather than sentiment. Slow update enforcement, missing Apple-specific controls, a self-service catalogue people will not use, and new macOS features arriving late are four different complaints with four different answers. One of them is fixed by configuration rather than by procurement.
"Do we still need Apple Business?" Yes, and no alternative avoids it. Automated device enrollment belongs to Apple rather than to whichever platform talks to it, so the dependency survives any switch you make.
"What happens to conditional access?" If device compliance currently gates resource access through Entra ID, establish precisely how a replacement would reproduce that before committing. Test it by failing a device deliberately and confirming access is actually blocked, rather than reading the documentation.
"Will two consoles actually be worse?" Not necessarily, and running both deliberately is a legitimate answer. The version that goes wrong is running two by accident, with policies that drifted apart and nobody owning the reconciliation.
What Intune Actually Includes
Worth establishing before shopping, because a surprising number of teams do not know what they already hold.
Intune Plan 1 capability is included with Microsoft 365 E3 and E5. That covers device enrollment and management across Windows, macOS, iOS and Android, configuration profiles, compliance policies, application deployment, and the conditional access tie-in through Entra ID. Plan 2 is available for organisations wanting the additional capabilities without the wider suite.
For Macs specifically, the core management surface is present: enrollment through Apple Business, configuration profiles, compliance policies, FileVault enforcement and application deployment. What lags is timing and depth. Apple ships a major macOS release every autumn, and new management capabilities arrive later in the cross-platform suites than in the Apple specialists. Some Apple-specific controls are shallower. Neither is a secret and neither is a scandal. It is the predictable consequence of a platform that must support four operating systems rather than one.
There is one more thing the licence does not include, and it causes more frustration than any missing feature: somebody who knows Apple deployment. Owning Intune does not mean anybody in the building can configure Apple management inside it, and the Intune community, while enormous, is overwhelmingly focused on Windows. An unusual macOS question has far fewer existing answers than the same question asked of Jamf, and that gap shows up in the first month rather than the first year.
The Three Kinds of Intune Alternative
Apple specialists, alongside rather than instead
Jamf, Mosyle, Iru. They do not manage Windows, so this is not a replacement. It is a deliberate two-platform arrangement where Intune keeps the Windows estate and an Apple tool takes the Macs.
Right when: Apple is a significant and vocal minority, and the Mac complaints are specific rather than general.
Fails when: nobody owns the reconciliation between the two, which is how two deliberate platforms become two accidental silos.
Cross-platform suites, instead of
Hexnode, Scalefusion, NinjaOne, ManageEngine. One console for everything, which is what Intune already is, so the argument has to be that they do it better or more simply or more cheaply.
Right when: you do not hold Microsoft 365 E3 or E5, which removes Intune's strongest argument entirely, or the Intune administrative surface is genuinely the problem.
Fails when: you need the native conditional access tie-in, which is Microsoft's home advantage.
Apple's own free management, as a floor
Apple Business. Since 14 April 2026 Apple has retired Apple Business Manager, Apple Business Essentials and Apple Business Connect, replacing all three with one free platform that includes Apple's first built-in mobile device management, with Blueprints for groups, settings and apps.
Right when: the Mac population is small and the requirements are basic. Worth trying before buying, because you need the platform for enrollment regardless.
Fails when: you need depth, scripting, patch management or auditor-facing reporting.
| Kind | Options | What you are actually doing |
|---|---|---|
| Apple specialists | Jamf, Mosyle, Iru | Keeping Intune, adding a second platform on purpose |
| Cross-platform suites | Hexnode, Scalefusion, NinjaOne, ManageEngine | Replacing Intune, giving up a licence you may already own |
| Apple's own | Apple Business | Raising the floor for free, not replacing anything |
Running Intune and an Apple Tool Together, Concretely
This arrangement gets mentioned in every Intune comparison and described in almost none, which is unhelpful because it is the answer for a large share of readers. Here is what it actually involves.
Intune keeps the Windows estate and the identity layer. Nothing changes there. Conditional access, compliance policies and resource gating continue to run through Entra ID as they do now, which is the capability you are specifically not giving up.
The Apple tool takes the Macs, including enrollment. Devices move out of Intune management and into the Apple platform, which means unenrolling and re-enrolling each one. This is the work, and it is the part that takes weeks on a distributed fleet.
Compliance state flows back. Jamf integrates with Intune for device compliance, so a Mac managed by Jamf can report its state into Microsoft's conditional access and a non-compliant machine can still be blocked. This single integration is what makes the arrangement practical rather than merely tolerable, and it is the specific thing to test before committing.
Each platform gets a named owner. Not the same person for both, ideally, and definitely not nobody. This is the difference between two platforms and two silos, and it is an organisational decision rather than a technical one.
One reconciliation routine, written down. A monthly or quarterly check that both consoles agree about the fleet, and that a compliance question can be answered across all devices in one go rather than by exporting from two systems into a spreadsheet.
| Concern | Who owns it | What goes wrong without a decision |
|---|---|---|
| Windows devices | Intune | Nothing, this is unchanged |
| Mac devices | The Apple platform | Macs sit in both, or in neither |
| Identity and conditional access | Intune via Entra ID | Access gating stops covering Macs |
| Mac compliance reporting | Apple platform, fed into Intune | Two reports nobody reconciles |
| Enrollment setup | Apple Business, shared by both | Automated enrollment quietly fails |
| Reconciliation between consoles | A named person, on a schedule | An auditor finds the inconsistency first |
The practical test for whether it is working is one question: can anybody answer a compliance question across the whole fleet in a single operation? If producing an encryption report means exporting from two systems and reconciling them manually, you do not have two platforms. You have two silos and a spreadsheet between them, which is survivable at a hundred devices and genuinely risky at a thousand.
And the honest cost: two renewal conversations, two sets of policies to keep aligned, two vendors to argue across during an incident, and one more item in a vendor risk assessment. None of that makes the arrangement wrong. It is simply what you are buying, and it should be a decision rather than a drift.
How to Choose: Five Questions Before You Talk to Any Vendor
Check what your Microsoft licences include. First, before anything else. If E3 or E5 is in place, Intune is paid for and the comparison starts from a different place than most articles assume.
Count the Macs as a percentage. Not the absolute number. Twenty per cent and sixty per cent point at opposite conclusions, and the figure takes an afternoon to establish.
Establish whether the Apple side was ever properly configured. Ask who built it and what they knew about Apple deployment. If the answer is nobody in particular, you may be shopping for a solution to a staffing problem.
Write down your conditional access requirement. From whoever owns it. If device compliance must gate resource access, that requirement eliminates options and it should do so early rather than during a pilot.
Decide replace or supplement, explicitly. Then only look at tools that fit the decision. Most wasted time in this comparison comes from evaluating Apple-only platforms as if they were Intune replacements.
Six Alternatives Worth Knowing
Pricing is what each vendor published on its own site, checked on 3 October 2026. Where a vendor does not publish a figure that can be attributed to a specific plan, this says so rather than guessing.
Apple Business
Best for: a small Mac population inside a Microsoft estate, and anybody wanting to establish requirements before buying.
Why teams choose it: free, from Apple, and required for automated enrollment whatever else you run. Blueprints handle groups, device settings, security and apps with no licence conversation and no procurement cycle.
Where it struggles: no scripting, no third-party patch management, and reporting well short of auditor-facing. It also does not touch Windows, so it supplements rather than replaces.
Pricing: free.
Jamf
Best for: an Apple population significant enough to deserve a specialist, kept alongside Intune rather than instead of it.
Why teams choose it: the deepest Apple management available, the fastest support for new macOS capabilities, and the largest body of worked knowledge in the category, which matters because so much real Apple configuration work is solved by finding somebody who hit the same problem first.
Where it struggles: no Windows, so it is never a full replacement. It also assumes an administrator who will use the depth, and a team that could not configure Apple management in Intune may not fare better here.
Pricing: Jamf for Mac is $12.50 per macOS device per month, billed annually, with a 25-device minimum, bundling Jamf Pro with Jamf Connect and Jamf Protect. Jamf for Mobile is $5.75 per mobile device per month. Jamf Now starts at $4 per device per month.
Worth knowing: Jamf integrates with Intune for device compliance, so a Mac managed by Jamf can report compliance state into Microsoft's conditional access. That integration is the main reason the two-platform approach is practical rather than merely tolerable, and it is the specific thing to evaluate if you are leaning that way.
Mosyle
Best for: Apple populations that need capability without an Apple specialist on staff.
Why teams choose it: built exclusively for Apple, with automation that works without assembly, and a free tier genuinely usable for small fleets. For a team whose Mac complaints are about day-to-day friction rather than missing enterprise features, it addresses the complaint directly.
Where it struggles: Apple only, so Intune stays for Windows. Pricing is not published in a form that can be verified externally, so budgeting means a conversation.
Hexnode
Best for: teams that do not hold E3 or E5 and want one console with a published rate card.
Why teams choose it: Apple, Windows and Android from one place, with pricing you can read without a sales call. For an organisation without the Microsoft licensing entitlement, this is often the most direct comparison to Intune on equal terms.
Where it struggles: second-best at Apple, like Intune, so it does not fix an Apple depth complaint. Conditional access comes through integration rather than natively.
Pricing: on annual billing, $2.20 per device per month for Pro, $3.20 for Enterprise, $4.70 for Ultimate and $5.40 for Ultra. Monthly billing is $2.40, $3.60, $5.20 and $6.00.
Scalefusion
Best for: mixed fleets including shared, kiosk and rugged devices.
Why teams choose it: broad device-type coverage beyond laptops and phones, which matters for frontline and shared-device environments that general-purpose suites handle awkwardly.
Where it struggles: the Apple depth question is the same as Intune's, so it does not answer a Mac-specific complaint. Enterprise identity integration is less native than Microsoft's.
Pricing: published per-device, starting at $2 per device per month on annual billing. Higher tiers are published on the same page, so the full rate card is readable without a sales conversation.
NinjaOne
Best for: teams wanting management and monitoring in one tool, particularly where endpoints are the unit of work.
Why teams choose it: it combines device management with monitoring and patching in a way that suits IT teams operating reactively as well as administratively, and it publishes its pricing shape openly.
Where it struggles: its pricing model inverts the usual assumption, which catches smaller teams out. Apple depth is not its strength either.
Pricing: per-device, and it varies by volume in the opposite direction to most expectations. NinjaOne states it starts as low as $1.50 per device per month at 10,000 endpoints, rising to $3.75 at 50 or fewer endpoints. If you are small, you pay the higher end.
What Each One Published
| Platform | Published price | Covers Windows | Apple depth | Against Intune |
|---|---|---|---|---|
| Apple Business | Free | No | Basic | Supplements, cannot replace |
| NinjaOne | $1.50 to $3.75 per device | Yes | Second | Cheaper if large, dearer if small |
| Scalefusion | From $2.00 per device | Yes | Second | Real replacement without E3 or E5 |
| Hexnode | $2.20 to $5.40 per device | Yes | Second | Real replacement without E3 or E5 |
| Jamf for Mac | $12.50 per Mac | No | Deepest | Supplements, integrates for compliance |
| Mosyle | Not published | No | Deep | Supplements, free tier available |
| ManageEngine | Annual licence tiers | Yes | Second | Published, but not directly per-device comparable |
| Microsoft Intune | Included with E3 and E5 | Yes | Second | The incumbent you may already own |
Read the fifth column before the second. Three of these cannot replace Intune at all, which does not disqualify them, because supplementing is a legitimate and often better answer. It does mean a price comparison against Intune is meaningless for those rows.
The NinjaOne row deserves a second look if you are under a hundred devices. Volume pricing that moves against you is unusual enough that teams budget from the headline figure and are surprised by the quote.
The Decision Table
| Situation | Scale | Setup | Primary Pain | Recommended Starting Point |
|---|---|---|---|---|
| Hold E3 or E5, Macs a small minority | Any | Any | Mac friction, licence already paid | Configure Intune properly first |
| Hold E3 or E5, vocal Mac minority | 100 plus | Mixed | Apple depth on real users | Keep Intune, add Jamf or Mosyle |
| No Microsoft 365 entitlement | 50 to 500 | Mixed | Paying for Intune outright | Hexnode or Scalefusion |
| Apple is most of the fleet | 50 to 500 | Any | Weaker tool on the majority | Jamf or Mosyle, Intune for the rest |
| Small Mac population, basic needs | Under 25 Macs | Any | Overhead of a second licence | Apple Business, free |
| Shared, kiosk or rugged devices | Any | Frontline | Device types suites handle badly | Scalefusion |
| Large endpoint count, want monitoring too | 1,000 plus | Any | Two tools doing one job | NinjaOne |
The first row is the one most often skipped, and it is the cheapest outcome available. A properly configured Apple side inside a licence you already hold beats a second platform nobody has budgeted for, and establishing which you have takes a conversation rather than a procurement cycle.
Where Teams Get This Switch Wrong
Shopping before checking the licence. Buying device management while holding E3 or E5 that already includes Intune Plan 1 capability. It happens regularly, it is a real recurring cost paid for nothing, and it takes ten minutes to rule out.
Evaluating Apple-only tools as Intune replacements. They are not, and a shortlist mixing Jamf with Hexnode is comparing two different decisions. Decide replace or supplement first, then build the list.
Mistaking configuration for capability. An Intune tenant pointed at Macs without anybody learning Apple deployment produces the same complaints any badly configured platform would. Establish which you have before concluding the product is at fault.
Ignoring the conditional access dependency. If compliance currently gates access natively through Entra ID, reproducing that elsewhere means an integration. Test it by failing a device on purpose and confirming access is actually blocked, because this is precisely the kind of thing that works exactly as documented until a particular identity configuration is involved.
Letting two platforms happen by accident. Running Intune and an Apple specialist deliberately, with a named owner for each and a documented reason, is a sound arrangement. Drifting into it is not, and the difference shows up at the audit as two compliance reports nobody reconciles.
Budgeting from a headline figure without checking the volume curve. Most per-device pricing gets cheaper as you grow. NinjaOne publishes the opposite shape. Model your own device count rather than reading the lowest number on the page.
Switching to escape complexity. Intune is demanding. So is any platform managing four operating systems across a real estate at real scale. A simpler tool that does less is sometimes the right answer and is never automatically the right answer, and the complexity frequently reappears about four months after migration.
What None of Them Will Tell You
Every platform here knows about devices it manages, which sounds complete until you need the other list.
None can tell you about a machine that was never enrolled, because none has seen it. None can tell you where a laptop physically is, only where it last checked in from. None can tell you whether the machine issued to somebody who left in March came back, only that it stopped reporting. And none can tell you what you own, which is the question an auditor actually asks.
That is an asset management gap rather than a shortcoming of any product here, and no amount of platform switching touches it. The fix is a register alongside the MDM rather than a different MDM. Platforms built for that side of the problem, such as RemoAsset, handle procurement, delivery and physical retrieval, with enrollment happening on delivery. RemoAsset is not an MDM and does not replace anything on this list.
This is worth saying plainly in an Intune comparison specifically, because a tenant migration is a convincing-looking way to spend a quarter on the wrong problem. The work is real, the plan is legible, progress is reportable every week, and at the end of it the laptops still do not come back. Ask what actually went wrong last quarter. A misconfigured or unpatched machine is an MDM problem. A laptop nobody can account for is not.
What to Establish Before You Commit
What your Microsoft licences include. E3, E5, Plan 1, Plan 2. Before anything else, because the answer reframes the whole comparison.
The Mac percentage, written down. The single most decisive number and the one least often established.
Who configured the Apple side, and what they knew. This separates a product problem from a staffing problem, and the two have different fixes.
The conditional access requirement, from its owner. In writing, in one sentence, from security or compliance rather than IT.
Replace or supplement, decided explicitly. Then a shortlist that matches, rather than one mixing both.
The specific Mac complaints, itemised. Not sentiment. Four named problems, each of which can be checked against a candidate during a trial.
Your device count on each vendor's own volume curve. Particularly where that curve runs the unusual way.
None of those seven requires a vendor conversation. They are answerable inside your own organisation in about a day, and together they eliminate most of this page before anybody books a call.
What Getting This Wrong Costs
The first cost is paying twice, and it is the most common. A new platform licence alongside a Microsoft entitlement that already covered it, running until somebody notices at renewal. Visible, recoverable, embarrassing.
The second is the migration, which is larger than vendors suggest and larger again on a mixed fleet. Every device unenrolled and re-enrolled, across two or three operating systems, with the stragglers taking weeks. On a distributed fleet that means asking people to act on their own machines, and the tail is always longer than the plan. Migrating new hires first makes this considerably less painful, because every device issued after the switchover date arrives on the new platform with no user involvement at all.
The third lands at the audit and costs something other than money. Platform changes are exactly when enrollment coverage slips, because nobody tracks the un-migrated tail to zero. A year later the compliance evidence has a hole in it, discovered by somebody who is not on your side. Track to completion rather than to mostly done.
The fourth is specific to this comparison and the most avoidable. Switching away from Intune to fix an Apple complaint, and discovering the replacement is also second-best at Apple, because most cross-platform suites make the same trade for the same reason. If Apple depth is genuinely the problem, only an Apple specialist fixes it, and that means supplementing rather than replacing.
When You Are Ready to Decide
Check the licence first. If E3 or E5 is in place, Intune is paid for, and the question becomes whether the alternative is better by enough to justify a second line item. For many teams the honest answer is no, and the cheaper fix is configuring the Apple side properly inside the platform they already own.
Then decide replace or supplement, out loud, and build a shortlist that matches. Apple specialists supplement. Cross-platform suites replace. Mixing them in one comparison is how months get spent.
Then trial on real devices rather than spares. Enroll a machine belonging to somebody in the design team who will complain, push a policy they will notice, produce the specific compliance report you are actually asked for, and fail a device deliberately to confirm conditional access still blocks it. Give the trial to the person who will own the platform, not to whoever is most curious.
And if the Mac population is small and the requirements are basic, try Apple Business first. It is free, you need it for enrollment regardless, and finding out what it cannot do with your own devices is better research than any vendor call.
One closing observation that applies to this comparison more than most. Intune is the only platform here that many readers already own, which makes it the only one where the alternative has to clear a bar rather than merely look attractive. That bar is not a high one if Apple is most of your fleet. It is a very high one if Macs are a fifth of it and the real complaint is that nobody has had time to configure the Apple side properly. Working out which of those two you are is the whole exercise, and it costs a conversation rather than a budget.
Frequently Asked Questions
What is the best alternative to Microsoft Intune?
It depends on whether you are replacing Intune or supplementing it, and that distinction decides more than any feature comparison. If Apple depth is the complaint and Macs matter, the answer is to keep Intune for Windows and add Jamf or Mosyle for the Apple estate, because the Apple specialists do not manage Windows and so cannot replace Intune at all. If you do not hold Microsoft 365 E3 or E5 and are paying for Intune outright, Hexnode and Scalefusion are genuine one-console replacements with published per-device pricing. And if your Mac population is small with basic requirements, Apple Business has been free since April 2026 and is worth trying before buying anything.
Is Intune included with Microsoft 365?
Intune Plan 1 capability is included with Microsoft 365 E3 and E5, which is the single most important fact in this comparison and the one most often missed. If you hold either licence, the marginal cost of managing devices with Intune is nothing, so every alternative represents a new line item rather than a swap. Plan 2 is available for organisations that want the additional capabilities, and there are standalone options for those not buying the wider suite. Before evaluating any alternative, confirm exactly which Microsoft licences your organisation holds, because teams regularly buy device management they were already entitled to.
Is Intune good enough for Macs?
For most organisations where Macs are a minority, yes. The core management surface is present: enrollment through Apple Business, configuration profiles, compliance policies, FileVault enforcement and application deployment, with device compliance tying natively into conditional access through Entra ID. What lags is timing and depth, because new macOS capabilities arrive later than in the Apple specialists and some Apple-specific controls are shallower, which is most visible each autumn when Apple ships a major release. At eighty per cent Windows that compromise affects a fifth of your devices and the saving is real. At sixty per cent Apple it is a trap, because you accept the weaker tool on most of your estate to avoid a licence you would gladly pay for.
Can I run Intune and Jamf together?
Yes, and it is a more common arrangement than the either-or framing suggests. Jamf integrates with Intune for device compliance, so a Mac managed by Jamf can report its compliance state into Microsoft's conditional access, which is the specific capability that makes the two-platform approach practical rather than merely tolerable. The cost is maintenance: two consoles, two policy sets, two compliance reports to reconcile, two renewal conversations and a standing requirement that somebody understands both. The version that works has a named owner for each platform and a documented reason. The version that fails is the one nobody decided on, where the two drift apart and an auditor finds the inconsistency.
Do I still need Apple Business if I leave Intune?
Yes, and no platform avoids it, because the enrollment capability belongs to Apple rather than to whichever product is talking to it. Apple Business is what enables automated device enrollment, where a Mac enrolls itself during first setup rather than depending on somebody installing a configuration profile they could later remove, and it handles volume app purchasing and Managed Apple Accounts. It replaced Apple Business Manager, Apple Business Essentials and Apple Business Connect on 14 April 2026 and is free in more than 200 countries. Whatever you switch to, that dependency survives the switch, along with the rule that devices must be bought through Apple or an enrolled reseller to appear in automated enrollment.
Why is NinjaOne cheaper for large fleets than small ones?
Because its published per-device pricing moves with volume in the direction most people do not expect. NinjaOne states that it starts as low as $1.50 per device per month at 10,000 endpoints and rises to $3.75 at 50 or fewer endpoints, so a small team pays the higher end rather than the headline figure. This is worth flagging because the normal assumption is that per-device pricing only gets better as you grow, and a team of forty budgeting from the lowest published number will be surprised by the quote. The practical lesson applies beyond this one vendor: model your own device count against each vendor's own curve rather than reading the most attractive figure on the page.
Is Intune too complicated?
It is genuinely demanding, and that is a fair complaint rather than a failure of understanding. It is also worth testing against a question: demanding compared to what? Any platform managing Windows, macOS, iOS and Android across a real estate at real scale carries comparable weight, and a simpler tool is usually simpler because it does less, which may or may not be the trade you want. The cases where complexity genuinely justifies leaving tend to involve inherited configuration nobody understands, or co-management arrangements layered over older tooling. The cases where it does not tend to resolve about four months after migration, when the new platform has accumulated the same conditions for the same reasons.
Will switching MDM fix our missing laptops?
No, and this is the most expensive misdiagnosis in the category because the project looks so much like progress. Every platform here knows about devices it manages and reports where they last checked in from, which is not the same as knowing where a machine physically is, whether the laptop belonging to somebody who left in March came back, or what hardware you own but never enrolled. That is an asset management gap rather than a shortcoming of any MDM, and the fix is a register alongside the platform rather than a different platform. Ask what actually went wrong last quarter: a misconfigured, unpatched or unencrypted machine is an MDM problem, and a laptop nobody can account for is not.