TL;DR
- The usual reason people look: not that Jamf is bad, but that nobody on the team has time to operate it properly, so an expensive platform runs basic policies.
- When you should stay: if an administrator is actively using the scripting layer and the policy structure. Nothing here replaces that depth.
- What Jamf costs now: $12.50 per Mac per month, billed annually, 25-device minimum. That figure is a bundle of Jamf Pro, Jamf Connect and Jamf Protect, not management alone.
- The cheapest alternative is free: Apple Business replaced Apple Business Manager in April 2026 and includes Apple's own built-in MDM at no cost.
- The decision rule: work out whether your problem is depth, price, or staffing. Those have three different answers and only one is a product comparison.
- The outcome: a platform matched to the person who will actually operate it, rather than to the capability you hoped to grow into.
The Renewal That Starts the Search
A company of 140 with 110 Macs gets its Jamf renewal. The number is not a surprise. What prompts the conversation is a question from finance about what the platform is doing, and the honest answer is that it enforces disk encryption, pushes updates and deploys about six applications.
All three of those things could be done by something cheaper. Some of them could be done for nothing.
That is the shape of most Jamf alternative searches, and it is worth naming because it changes what you are shopping for. The problem is rarely that Jamf lacked a capability. It is that the capability which justified the purchase was never staffed, so the organisation bought a platform for an administrator it did not hire.
Best tools for Device Management
There is a second, much better reason to look, and it is worth separating from the first. Sometimes the fleet changed. A company that was all Mac acquires one that is all Windows, and suddenly the best Apple platform in the category is managing a minority of the estate. That is a genuine fit problem rather than a utilisation problem, and it points somewhere different.
A third reason is more specific, and worth naming because it is the one people are reluctant to say out loud. The person who set Jamf up has left. What remains is a configuration nobody fully understands, which still works, and which nobody will touch. That is not a product problem either, and switching platform to escape it is an expensive way to get a clean slate. It is sometimes the right call anyway, because inheriting an unowned configuration is a real operational risk, but it should be made deliberately rather than dressed up as a cost saving.
What all three have in common is that the question is about your organisation rather than about Jamf. That is why the next section is an audit rather than a comparison.
When You Should Not Replace Jamf
When somebody is using the depth
The clearest signal is scripts. If an administrator maintains extension attributes, writes configuration profiles by hand, and has built a policy structure that reflects how your organisation actually works, you are getting what you pay for and every option below is a downgrade.
The test is specific: ask what Jamf does that the person could not achieve in a simpler tool. If they can answer in detail, stay.
When your compliance evidence depends on it
If an auditor, an insurer or a customer security questionnaire is satisfied by reports you currently produce from Jamf, changing platform means rebuilding that evidence trail and re-establishing confidence in it. That is possible and it is not free, and the cost lands on the person who least wants it.
When the Apple community is doing your research
This is underrated. A large share of real Apple configuration work is solved by finding somebody who already hit the same problem and published what they did, and Jamf's community is the largest in that specific domain by a wide margin. Leaving it means that an unusual question has far fewer existing answers, and you will notice in the first month.
When the migration is larger than the saving
Every device must be unenrolled and re-enrolled. Across 400 distributed machines that is a programme, not a project, and the licence difference rarely justifies it inside one budget year. Price the migration before the licence.
Five Questions Teams Ask Before Switching
"Are we actually paying for things we do not use?" Open the console and count the policies in active use, the scripts in the library, and the last time either changed. That audit takes an hour and settles the question more reliably than any vendor comparison.
"Will a cheaper platform enforce the same things?" For disk encryption, OS updates, basic restrictions and app deployment, almost certainly yes, including the free option. For anything conditional, scripted or custom, less likely.
"What happens to our enrollment?" Nothing automatic. Devices stay enrolled in Jamf until each one is individually moved, so there is no cutover and no outage, but you operate two consoles for however long the tail lasts.
"Is the free Apple option real?" Since April 2026, yes. Whether it is enough depends on your compliance obligations more than your device count.
"Who will own the new platform?" If the answer is the same person who did not have time for Jamf, choose a platform that assumes less of them. If the answer is a new hire, the depth argument changes entirely and you may be solving the wrong problem.
What Jamf Actually Costs
Worth establishing precisely, because this comparison used to be impossible to make.
Jamf publishes list pricing on its own site, which it did not always do. Jamf for Mac is $12.50 per macOS device per month, billed annually, with a 25-device minimum. Jamf for Mobile is $5.75 per mobile device per month on the same terms. Jamf Now, a lighter product aimed at smaller teams, starts at $4 per device per month.
The detail that matters when comparing: the $12.50 figure is a bundle. It covers Jamf Pro for management, Jamf Connect for identity and Jamf Protect for endpoint security, rather than pricing the management product on its own. Setting it against a management-only licence from another vendor is not a fair comparison, and it is the mistake most roundups make.
That cuts both ways. If you are separately paying for endpoint protection and an identity bridge, the bundle may be closer to competitive than the headline suggests. If you are using Jamf purely for management and have security covered elsewhere, you are paying for two products you do not need, and that is a stronger reason to look than the headline number.
So the useful exercise is not comparing $12.50 against a cheaper figure. It is listing what the bundle covers, striking out what you already buy elsewhere, and comparing what remains.
| What the bundle covers | What it does | Do you already pay for this? |
|---|---|---|
| Jamf Pro | Device management, policies, scripting | This is the part you are comparing |
| Jamf Connect | Identity, login tied to your directory | Often covered by Entra ID or Okta |
| Jamf Protect | Endpoint security, threat detection | Often covered by an existing EDR tool |
Work down that third column honestly. A team already running Entra ID for identity and a separate endpoint security product is paying for two thirds of a bundle it does not need, and that is a far stronger argument for switching than any headline comparison. A team with none of those covered is getting three products for one price, and the alternatives are less cheap than they look once you add the two things you would have to buy separately.
The Utilisation Audit, Concretely
This gets recommended constantly and described almost never, so here is the whole thing. It takes about an hour and it is the only step on this page that can tell you to stop reading.
Count the policies that are actually scoped and enabled. Not the total in the list. The ones targeting a real smart group with devices in it. A console with forty policies where nine are scoped is a normal finding, and it is the finding that matters.
Open the scripts library and check the last modified date on each. Scripts are the clearest evidence of the depth you are paying for. If the newest one is three years old and was written by somebody who has left, you are maintaining an inheritance rather than using a capability.
List your extension attributes and ask what reads them. Extension attributes exist to collect information Jamf does not gather natively, so each one was created for a reason. If nobody can name the report or smart group consuming it, it is no longer doing anything.
Check how many devices are out of scope entirely. Enrolled but in no meaningful group, or not enrolled at all. This number is almost always larger than expected, and it changes which migration you are facing.
Identify the three things that would break if Jamf disappeared on Friday. Write them down. If all three are disk encryption, operating system updates and app deployment, every option on this page covers them, including the free one. If one of them is a scripted workflow nobody else can reproduce, you have your answer and it is to stay.
Ask who has logged in during the last ninety days. A platform with one occasional administrator and a licence for a hundred and ten devices is not a capability problem. It is an ownership problem, and moving platform without fixing ownership relocates it rather than solving it.
Write the six answers on one page. That page, rather than any vendor comparison, is what should go into the renewal conversation, because it is the only document in this process that describes your organisation rather than somebody's product.
The Three Kinds of Jamf Alternative
Apple specialists that assume less of you
Mosyle, Iru and Addigy. Built for Apple only, with pre-built automation rather than a scripting layer you maintain. The trade is a lower ceiling in exchange for a much gentler start.
Right when: Apple is your fleet and nobody on staff is an Apple deployment specialist.
Fails when: you have requirements nobody anticipated, which is exactly what a scripting layer exists for.
Cross-platform suites
Microsoft Intune and Hexnode. One console for Apple, Windows and Android, with Apple support that is real and visibly second.
Right when: the fleet is genuinely mixed, or you already pay for Microsoft 365 and the Intune capability is sitting unused inside it.
Fails when: Apple is most of your estate, because you accept the weaker tool on the majority of your devices.
Apple's own free management
Apple Business. Since 14 April 2026 Apple has retired Apple Business Manager, Apple Business Essentials and Apple Business Connect and replaced all three with one free platform, which includes Apple's first built-in mobile device management along with Blueprints for groups, settings and apps.
Right when: small fleet, simple requirements, no compliance obligation.
Fails when: you need scripting, third-party patch management or auditor-facing reporting. It raised the floor rather than moving the ceiling.
| Kind | Options | The trade |
|---|---|---|
| Apple specialists | Mosyle, Iru, Addigy | Lower ceiling, far gentler start |
| Cross-platform suites | Microsoft Intune, Hexnode | One console, second-best at Apple |
| Apple's own | Apple Business | Free, but shallow on depth and reporting |
How to Choose: Five Questions Before You Talk to Any Vendor
Audit what you currently use, not what you have. Count active policies, scripts and the last change date. This is the single most useful hour in the process and almost nobody spends it.
Separate the three possible problems. Depth, price and staffing produce three different answers. Depth means you need a peer, price means you need a cheaper peer, staffing means you need a platform that assumes less. Teams routinely describe a staffing problem as a price problem.
Price the migration, not the licence. Every device unenrolled and re-enrolled. Work out what that means for remote staff before committing to a date, because that is the part that slips.
Check what you already own. If you hold Microsoft 365 E3 or E5, Intune Plan 1 capability is already included, and managing Macs with it has a marginal cost of nothing.
Try the free option first. Apple Business costs nothing and you need it for enrollment regardless. Establishing what it cannot do is better research than any vendor call, and it is the cheapest way to discover your real requirements.
Six Alternatives Worth Knowing
Pricing is what each vendor published on its own site, checked on 3 October 2026. Where a vendor does not publish, this says so rather than estimating.
Apple Business
Best for: small Apple fleets and anybody who wants to establish requirements before buying.
Why teams choose it: free, from Apple, and already required for automated enrollment whatever else you run. Blueprints cover groups, device settings, security and apps with no licence conversation.
Where it struggles: no scripting layer, no third-party patch management, and reporting that stops short of what an auditor-facing process needs. Depth is the trade for the price.
Mosyle
Best for: Apple-only teams that want real capability without an Apple specialist.
Why teams choose it: built exclusively for Apple, with automation that works without assembly, and a free tier that is genuinely usable rather than a limited trial. For a team leaving Jamf because nobody had time for it, this is the most common landing place.
Where it struggles: Apple only, so a mixed fleet needs a second tool. Pricing is not published in a form that can be verified from outside, so budgeting means a conversation.
Who actually leaves Jamf for it: the largest group by some distance. Teams whose audit showed basic policies, no active scripts and one occasional administrator. The move usually works, because the thing they were failing to use is the thing they stopped paying for.
Iru (formerly Kandji)
Best for: Apple fleets wanting drift corrected automatically rather than by scripts they maintain.
Why teams choose it: it checks devices against a desired state and remediates differences without an administrator writing the logic. That is the clearest philosophical opposite of Jamf's approach, and for the right team it is the whole argument.
Where it struggles: the name changed. Kandji rebranded to Iru on 22 October 2025 and kandji.io now redirects to iru.com, so inherited shortlists and procurement records may name a company that no longer exists under that name. Pricing is not published.
Who actually leaves Jamf for it: teams that want the outcomes the scripting produced without maintaining the scripts. If your audit found scripts that are genuinely load-bearing but written by somebody who has gone, this is the option worth testing first, because automated remediation is the closest available substitute for a departed author.
Microsoft Intune
Best for: organisations where Macs are a minority inside a Microsoft estate.
Why teams choose it: you very likely already own it, since Intune Plan 1 capability is included with Microsoft 365 E3 and E5, and device compliance ties natively into conditional access through Entra ID. For a Mac minority, the marginal cost is nothing.
Where it struggles: Mac support is capable and second. New macOS capabilities arrive later than in the Apple specialists, some Apple-specific controls are shallower, and the vast Intune community is overwhelmingly focused on Windows, so an unusual macOS question has far fewer answers waiting.
Hexnode
Best for: mixed fleets that want a published rate card.
Why teams choose it: Apple, Windows and Android from one console, with pricing you can read without a sales call. For an evenly split fleet, one adequate tool often beats two excellent ones and a reconciliation problem between them.
Where it struggles: second-best at Apple by design. If Macs are the majority, that compromise lands on most of your estate.
Pricing: on annual billing, $2.20 per device per month for Pro, $3.20 for Enterprise, $4.70 for Ultimate and $5.40 for Ultra. Monthly billing is $2.40, $3.60, $5.20 and $6.00.
Addigy
Best for: managed service providers and internal teams that operate like one.
Why teams choose it: built for managing many separate environments from one console, with monitoring and scripting aimed at people who do this professionally.
Where it struggles: multi-tenancy is overhead if you have one tenant, and it is the most expensive published option here, so it is rarely the answer to a cost-driven search.
Who actually leaves Jamf for it: almost nobody doing it for cost. The teams that move here are MSPs, or internal groups managing several legally separate entities after acquisitions, where the tenancy model is the feature rather than the overhead.
Pricing: plans start at $8.25 per Mac per month with no multi-year contract required. The Security Suite starts at $16 per Mac per month. Lower per-device rates are available for MSPs.
What Each One Published
| Platform | Published price | Unit | Against Jamf at $12.50 |
|---|---|---|---|
| Apple Business | Free | n/a | No licence cost, much less depth |
| Hexnode | $2.20 to $5.40 | per device, per month | Cheaper, cross-platform, second at Apple |
| Addigy | From $8.25 | per Mac, per month | Cheaper headline, MSP-shaped |
| Mosyle | Not published | n/a | Free tier exists, paid tiers quote |
| Iru | Not published | n/a | Formerly Kandji |
| Microsoft Intune | Included | per user | Nothing extra if you hold E3 or E5 |
The last column is the one to read carefully. A cheaper headline is not a saving if the thing you cut was load-bearing, and it is not a saving at all in the year you pay for a migration.
The Decision Table
| Situation | Scale | Setup | Primary Pain | Recommended Starting Point |
|---|---|---|---|---|
| Jamf running basic policies only | Any | Any | Paying for unused depth | Apple Business, then Mosyle |
| All Apple, no Apple admin | 10 to 200 | Distributed | Nobody owns the tooling | Mosyle or Iru |
| Administrator actively scripting | Any | Any | None, this is working | Stay on Jamf |
| Macs became a minority after a merger | 100 plus | Mixed | Two platforms, one estate | Microsoft Intune |
| Evenly split fleet, want one rate card | 100 to 500 | Mixed | Budgeting without a sales cycle | Hexnode |
| Audit obligation, depth genuinely used | 50 to 500 | Any | Rebuilding evidence is the risk | Stay on Jamf |
| Managing many client environments | Any | Multi-tenant | Tenants, not devices | Addigy |
Two rows say stay, and that is deliberate rather than a hedge. Jamf is the best Apple management platform available and the reason to leave is almost never capability. If your row says stay, the saving you are chasing does not exist.
Where Teams Get This Switch Wrong
Treating a staffing problem as a pricing problem. The most common error by a wide margin. Moving to a cheaper platform does not create the administrator you did not hire. It does reduce how much administrator the platform needs, which is a real fix, but only if you choose on that basis rather than on price.
Comparing the bundle to a single product. Jamf at $12.50 includes management, identity and endpoint security. Comparing that against management-only pricing elsewhere makes the alternative look better than it is, unless you genuinely have the other two covered.
Migrating everything at once. The tactic that makes this much less painful is moving new hires first. Every machine issued after the switchover date arrives on the new platform with no user involvement at all, and you work backwards through the existing fleet at whatever pace people cooperate. The tail gets longer and the disruption gets much smaller.
Not testing the compliance report. The thing you will be judged on is whether you can produce device evidence on demand. Produce the specific report you are actually asked for, with your own devices in it, during the trial. It is unglamorous and almost never part of a demo.
Leaving without an exit audit. Before the last device moves, export what Jamf knows. Once the licence lapses, that history is gone, and some of it is the only record of what was configured and when.
Shortlisting from an article that was not fact-checked recently. This category moves quickly. Kandji became Iru in October 2025, Apple Business Manager was retired in April 2026, and Jamf started publishing prices having previously refused. A roundup carrying any of those as current tells you how recently somebody checked.
What None of Them Will Tell You
Every platform here knows about devices it manages. That sounds complete until you need the other list.
None of them can tell you about a Mac that was never enrolled, because none has seen it. None can tell you where a laptop physically is, only where it last checked in from. None can tell you whether the machine assigned to somebody who left in March came back, only that it stopped reporting.
That is an asset management gap rather than a shortcoming of any product here, and switching platform does not touch it. The fix is a register alongside the MDM rather than a different MDM. Platforms built for that side of the problem, such as RemoAsset, handle procurement, delivery and physical retrieval with enrollment happening on delivery. RemoAsset is not an MDM and does not replace anything on this list.
The diagnostic is one question. Ask what actually went wrong last quarter. A misconfigured, unpatched or unencrypted machine is an MDM problem and this comparison is the right one. A laptop that never came back, or an audit that turned up hardware nobody had recorded, is not, and no amount of switching will address it.
This matters here more than in most comparisons, because a platform migration is a convincing-looking way to spend a quarter on the wrong problem. The work is real, the project plan is legible, somebody can report progress every week, and at the end of it the laptops still do not come back. If your utilisation audit found that Jamf was doing its job adequately and the actual pain is elsewhere, the honest conclusion is that this was never a tooling decision and the budget belongs in a different line.
What to Establish Before You Commit
The utilisation audit. Active policies, scripts in use, last change date. One hour, and it decides whether you should be reading this at all.
What the bundle covers that you pay for elsewhere. Endpoint security and identity, specifically.
The named owner of the new platform. If it is the same person who had no time for Jamf, choose accordingly.
The migration cost in people rather than money. How many remote staff must act on their own machines, and over how many weeks.
The compliance report you are actually asked for. Named, and tested during the trial.
What your Microsoft licences already include. Before you pay for anything.
An export of what Jamf currently knows. Inventory, configuration and policy history, taken before anything changes rather than during the migration.
None of those seven needs a vendor. They are answerable from inside your own organisation in about a day, and together they eliminate most of this list before anybody books a call. The reason teams skip them is that preparation does not feel like progress while a demo does, and the demo is the part that can safely wait.
If you only do one, do the utilisation audit. It is the only step that can tell you the answer is to stay, which is also the cheapest possible outcome of this entire exercise.
What Getting This Wrong Costs
The first cost is the obvious one and the easiest to recover from. You move to a cheaper platform, discover it cannot do something you needed, and move back or buy an additional tool. Annoying, visible, fixable at renewal.
The second is the migration itself, paid twice. Every device unenrolled and re-enrolled, then done again when the first choice turns out to be wrong. This is the real argument for being honest in the utilisation audit, because the audit is free and the second migration is not.
The third is quieter and lands at the audit. A platform change is exactly the moment enrollment coverage slips, because the tail of un-migrated machines is long and nobody tracks it to zero. A year later your compliance evidence has a hole in it, and the hole is discovered by somebody who is not on your side. Track the migration to completion rather than to mostly done, because mostly done is where that cost accumulates.
There is a fourth cost that only appears if you let the old licence lapse before finishing. Once Jamf is gone, so is its record of what was configured, when, and by whom. That history is occasionally the only documentation of a decision somebody made four years ago, and it is the kind of thing nobody misses until an incident review asks for it. Export before you cancel, rather than after you decide to.
And one cost that is usually overstated: user disruption. Re-enrollment is visible and mildly irritating rather than genuinely damaging, provided people know it is coming and why. The teams that report migrations going badly almost always announced the date before writing the explanation. The technical work is straightforward and the social part is what fails, which makes it the cheapest part to get right.
When You Are Ready to Decide
Do the utilisation audit first. If an administrator is actively using the scripting layer and the policy structure, stop here, because nothing on this list is an upgrade and the saving you are chasing is not real.
If the audit shows basic policies and an unused library, you have a staffing-shaped problem with a product-shaped solution. Start with Apple Business, which is free and which you need anyway, and find out what it cannot do with your actual requirements. Then look at Mosyle or Iru, which are built to need less of the person you do not have.
If the fleet changed rather than the usage, check your Microsoft licences before anything else. An Intune entitlement you already pay for is the strongest argument in this whole comparison and the one most often missed.
And whichever you pick, migrate new hires first and track the tail to zero.
One last framing worth holding onto. The strongest outcome of this exercise is often a decision not to switch, combined with a decision to actually staff the platform you already own. That is an unsatisfying answer because it does not produce a project, but a Jamf instance with an owner is better than any alternative on this page without one, and the reverse is also true. The platform is rarely the variable that decides whether device management works. The person is.
Frequently Asked Questions
What is the best Jamf alternative?
It depends which of three problems you have, and they get confused constantly. If nobody on staff has time to operate Jamf properly, the answer is a platform that assumes less of an administrator, which means Mosyle or Iru. If Macs became a minority of your fleet, the answer is almost certainly Microsoft Intune, because the capability is already included with Microsoft 365 E3 and E5 and the marginal cost is nothing. If you simply want to spend less and your requirements are genuinely basic, start with Apple Business, which has been free since April 2026. And if an administrator is actively writing scripts and maintaining a policy structure, there is no better alternative and you should stay.
How much does Jamf cost?
Jamf publishes list pricing, which it did not always do, though not for Jamf Pro on its own. Jamf for Mac is $12.50 per macOS device per month, billed annually, with a 25-device minimum, and that figure bundles Jamf Pro together with Jamf Connect and Jamf Protect rather than pricing management separately. Jamf for Mobile is $5.75 per mobile device per month on the same terms, and Jamf Now, aimed at smaller teams, starts at $4 per device per month. The bundling matters when comparing, because setting $12.50 against a management-only licence elsewhere is not a fair comparison unless you already cover identity and endpoint security some other way.
Is there a free alternative to Jamf?
Yes, and it changed in April 2026 in a way much published advice has not caught up with. Apple retired Apple Business Manager, Apple Business Essentials and Apple Business Connect on 14 April 2026 and replaced all three with a single free platform called Apple Business, which includes Apple's first built-in mobile device management along with Blueprints for configuring groups, device settings, security and apps. Mosyle also offers a free tier that is genuinely usable for small fleets rather than a limited trial. Neither matches Jamf on scripting, third-party patch management or auditor-facing reporting, but for a small fleet with simple requirements the free options are a real answer.
Is Mosyle better than Jamf?
Not better, and the comparison is more useful framed as different assumptions about who operates it. Jamf offers the deepest Apple management available and a scripting layer that lets an administrator handle requirements nobody anticipated, and in return it assumes somebody who will learn Apple deployment properly. Mosyle offers pre-built automation that works without that person, trading a lower ceiling for a much gentler start. For a team with a capable Apple administrator, Jamf is the stronger product. For a team whose Jamf instance runs six basic policies because nobody had time, Mosyle will likely do the same job with less effort and less cost.
How hard is migrating off Jamf?
Harder than vendors suggest, because every device must be unenrolled from Jamf and enrolled into the new platform, and there is no way to transfer management remotely without touching each machine. In an office that is a trolley and an afternoon. Across a distributed fleet it means asking each person to act on their own laptop, the stragglers take weeks, and you run two consoles until the last one completes. The tactic that reduces the pain most is migrating new hires first, so every machine issued after the switchover date arrives on the new platform with no user involvement, then working backwards through the existing fleet at whatever pace people cooperate.
Does Intune replace Jamf for Macs?
For organisations where Macs are a minority, generally yes, and the licence argument is the strongest one in this comparison. Core management is present: enrollment through Apple Business, configuration profiles, compliance policies, FileVault enforcement and application deployment, with device compliance tying natively into conditional access. What lags is timing and depth, since new macOS capabilities arrive later than in the Apple specialists and some Apple-specific controls are shallower, which is most visible each autumn when Apple ships a major release. At eighty per cent Windows that compromise affects a minority of devices. At sixty per cent Apple it is a trap.
What happened to Kandji?
Kandji rebranded to Iru on 22 October 2025, and kandji.io now redirects to iru.com. The product and its approach are unchanged, so capability comparisons still hold, but the name does not, which matters for two practical reasons. Inherited shortlists, internal runbooks and procurement records will name a company that no longer exists under that name, and any vendor comparison you are working from that predates late 2025 should be treated as dated on this point. If you are reading a 2026 roundup that still lists Kandji as a current brand, that is a reasonable signal about how recently the rest of its facts were checked.
Should we keep Jamf just for the community?
It is a weaker reason than the depth argument but a stronger one than people expect, and it deserves to be named rather than dismissed. A large share of real Apple configuration work gets solved by finding somebody who already hit the same problem and published what they did, and Jamf's community is the largest in that specific domain by a considerable margin. Leaving means an unusual macOS question has far fewer existing answers, and you tend to notice in the first month rather than the first year. On its own it does not justify the licence, but if you are close to the line on other grounds, it is a legitimate thumb on the scale.