Jamf vs Intune: A Practical Guide for Mixed Fleets Choosing One Console

Jamf vs Intune compared for 2026. The Mac percentage that decides it, what Intune already costs you inside Microsoft 365, and when running both is the honest answer.

Rachel Kim Rachel Kim • • 25 min read

TL;DR

  • The real question: not which is better, but whether Macs are your primary platform or a minority inside a Microsoft estate.
  • When you don't need to choose: under about 20 devices on one platform. Pick the one matching your hardware and move on.
  • Jamf's case: the deepest Apple management available, and the largest body of worked knowledge in the category.
  • Intune's case: you very likely already own it. Intune Plan 1 capability ships with Microsoft 365 E3 and E5.
  • Decision rule: count your Macs as a percentage of the fleet, then ask who administers it. Those two answers decide it.
  • The outcome: one console your admin can actually operate, not two nobody fully owns.

The Spreadsheet That Settles It

An IT lead opens a comparison grid with forty rows. Jamf wins eighteen. Intune wins fifteen. Seven are a draw. Nothing is settled and the meeting is tomorrow.

Then somebody asks how many Macs there are. The answer is 34, out of 290 devices. That one number settles what the grid couldn't, and it took four seconds.

The grid was not useless. It established that both platforms can do the job, which is worth knowing. What it could not do is weigh the rows against each other, because weighting requires knowing whose hardware matters most, and that is a fact about the company rather than about the software.

So the useful framing isn't feature-by-feature. These are both mature platforms and both do the core job. The decision is about which platform your organisation is actually built around, because the loser in that comparison is always going to be the one managing the hardware it treats as secondary.

That is worth stating bluntly because vendors have an interest in keeping the conversation on features. A feature comparison between two mature platforms produces a near-tie by construction, and a near-tie pushes the decision towards whoever ran the better demo. The fleet ratio is harder to argue with and takes an afternoon to establish.

There is a second question hiding behind the first, and it decides nearly as much: who is going to operate this on a Tuesday in eight months. Both platforms are good. Neither is usable by somebody fighting the interface, and the skills they assume are genuinely different rather than differently branded.

Free Weekly Briefing Stay ahead of what's changing in HR and people ops.

Join 4,200+ leaders getting practical insights every week — no fluff, just signal.

Join Free →

When You Don't Actually Need to Choose

Single platform, small fleet. All Macs under 20 devices, or all Windows. Take the obvious one. Mosyle or Jamf for the first, Intune for the second, and spend your time elsewhere.

When friction starts showing. Usually a compliance request. Somebody asks for encryption status across every device, and you can answer for one platform and not the other.

The second signal is onboarding time. When a new starter on the minority platform waits two days longer than everyone else because their machine needs manual setup, the gap has moved from an inconvenience to a recurring cost measured in salaries.

When it becomes a liability. Running two consoles with two policy sets and two evidence trails. It works, and it doubles the surface area for an audit finding, which is why teams consolidate.

The edge case that forces it. An acquisition. You inherit a fleet managed by the platform you didn't pick, and now the question is not which is better but which migration is cheaper.

There is one more case worth naming because it arrives quietly: a change in what the business sells. A company that moves into regulated work, or starts handling customer data under a contract with security schedules, suddenly needs device compliance evidence it never needed before. That requirement does not care which platform you prefer, and it frequently settles the question on its own.

Five Questions IT Leads Ask at 11pm

"What percentage of our fleet is Apple?" The decisive number. Above roughly half, Jamf's depth earns its keep. Below a quarter, Intune is almost certainly already paid for and good enough.

"Do we already pay for E3 or E5?" If yes, Intune Plan 1 capability is sitting unused. Microsoft 365 E3 is $39.00 per user per month and E5 is $60.00, both including it, and Plan 2 is $4.00 per user per month standalone.

"Who is going to run this?" Jamf rewards an administrator who knows Apple deployment and punishes one who doesn't. Intune rewards somebody already fluent in Microsoft's admin surfaces. These are different people.

The bus-factor version of that question is sharper: if that person left next month, could anybody else operate it? Device management tends to concentrate in one head, and Apple deployment knowledge is specialised enough that the answer is frequently no.

"Can we run both?" Yes, and plenty do. It is a legitimate answer and a more expensive one, in licences and in the attention of whoever maintains two sets of policies.

"What does the migration actually involve?" Every device unenrolled and re-enrolled. On a distributed fleet that means asking people to act on their own machines, and the stragglers take weeks.

"What happens to the devices we already manage?" They keep running under the old platform until each one is moved, so there is no cutover and no outage, but you operate two consoles for however long the tail lasts. Plan that overlap honestly rather than assuming a weekend will clear it.

What Jamf Actually Does

Jamf has been managing Apple devices longer than almost anyone, and the product reflects that accumulation.

It covers the full Apple management surface: automated enrollment through Apple Business, configuration profiles, software update enforcement, app deployment through Apple's volume purchasing, patch management for third-party software, and a scripting layer that lets an administrator do essentially anything the operating system permits.

That scripting layer is the real dividing line in practice. It is what lets Jamf handle requirements nobody anticipated, and it is also what makes the platform demanding, because a capability that broad assumes somebody willing to use it. Platforms with pre-built automation instead of scripting trade that ceiling for a much gentler start.

The part that doesn't show in feature grids is the knowledge around it. A large share of real-world Apple management is solved by finding somebody who already hit your problem, and Jamf's community is by far the biggest in this category. For an unusual configuration requirement, that is worth more than any single feature.

What it asks in return is an administrator. Jamf assumes somebody who will write configuration profiles, read Apple's deployment documentation and maintain a policy structure. Teams that expect to configure it in an afternoon are consistently surprised, and the capability goes unused without that person.

The failure mode is specific and worth recognising. An organisation buys Jamf for its depth, nobody has time to learn it properly, and six months later it is running a handful of basic policies that any cheaper platform would have handled. The licence renews, the depth stays unused, and the comparison that justified the purchase was never wrong, it was simply about a capability nobody was staffed to use.

Jamf publishes list pricing, which it did not always do, though not for Jamf Pro on its own. The Jamf for Mac plan is $12.50 per macOS device per month, billed annually, with a 25-device minimum, and it bundles Jamf Pro together with Jamf Connect and Jamf Protect rather than selling the management piece alone. Jamf Now, the lighter product aimed at smaller teams, starts at $4 per device per month. A standalone quote still needs a sales conversation, but you can build a budget before you have one.

What Intune Actually Does

Intune is Microsoft's endpoint management platform, covering Windows, macOS, iOS, iPadOS, Android and Linux from the same console as the rest of Microsoft's admin estate.

For Windows it is comprehensive, and for an organisation already using Entra ID, Defender and Microsoft 365, the integration is the product. Device compliance feeds conditional access, so a non-compliant machine loses access to corporate resources without anybody building that connection.

For Macs it is capable and visibly second. The core management surface is there: enrollment through Apple Business, configuration profiles, compliance policies, FileVault enforcement, application deployment. What lags is timing and depth. New macOS capabilities arrive later than they do in the Apple specialists, and some Apple-specific controls are shallower.

The timing gap matters most in the autumn. Apple ships a major macOS release every year, and the specialists support its new management capabilities faster than the cross-platform suites do. If your organisation updates promptly, that lag is a live operational issue each September rather than an abstract one.

The commercial logic is the strongest argument in its favour. Intune Plan 1 capability is included with Microsoft 365 E3 at $39.00 per user per month and E5 at $60.00. If you already hold those licences, managing Macs with Intune has a marginal cost of nothing. Plan 2 is $4.00 per user per month standalone for organisations that want it without the wider suite.

That argument is stronger than it sounds and weaker than it looks, depending on the ratio. At eighty per cent Windows it is close to decisive, because the Apple compromises affect a minority of devices and the saving is real. At sixty per cent Apple it is a trap, because you are accepting the weaker tool on most of your estate to avoid a licence you would gladly pay for if you priced the productivity cost.

The other thing the licence argument hides is the administrator question. Owning Intune does not mean somebody knows how to configure Apple management inside it, and Apple deployment in Intune is its own learning curve rather than a checkbox.

Where They Genuinely Differ

Dimension Jamf Pro Microsoft Intune
Apple depth Deepest available Capable, lags on new features
Windows management None Comprehensive
Pricing Not published, quote only Published, per user
Already owned? No Often, via M365 E3 or E5
Admin skill assumed Apple deployment knowledge Microsoft admin fluency
Community knowledge Largest in Apple management Enormous, mostly Windows-focused
Identity integration Works with major providers Native with Entra ID
Conditional access Via integration Built in

The pricing row is the one that decides most real cases, and not in the way people expect. Intune frequently wins not because it is cheaper but because it is already bought, which is a different argument and a strong one.

It is worth separating those two claims when you present this internally. Already bought is a sunk-cost observation and a good one, because the licence is being paid regardless. Cheaper is a comparison you can now actually make, because Jamf publishes a $12.50 per Mac per month list figure and the Intune capability inside an E3 licence has a marginal cost of nothing. Run both numbers at your real device count rather than conflating them, because a business case resting on the sunk-cost argument alone falls apart the moment somebody asks what the Jamf quote actually said.

The admin skill row decides most of the rest. Neither platform is hard for the right person, and both are miserable for the wrong one.

The community row deserves more attention than it usually gets. In Apple management, a large share of real configuration work is solved by finding somebody who already hit the same problem and published what they did. Jamf's community is the largest in that specific domain by a wide margin. Intune's community is enormous overall and overwhelmingly focused on Windows, so an unusual macOS question has far fewer existing answers. That difference does not appear on any feature grid and it shows up in the first month.

How to Choose: Five Questions Before You Talk to Any Vendor

Count the Macs as a percentage. Not the absolute number, the share. Thirty Macs in a fleet of 60 is a different decision from thirty in a fleet of 600, and only the percentage tells you which platform will be treating your hardware as the main event.

Check what Microsoft licences you hold today. Open the admin centre and look. Teams routinely discover they have been paying for Intune capability for two years without using it, which changes the economics of the whole comparison before any demo.

Name the administrator. Then ask which ecosystem they already know. An Apple-literate admin will be productive in Jamf in a week and frustrated in Intune for a month. The reverse is equally true.

Ask what compliance evidence you have to produce. If conditional access tied to device state is a requirement, Intune does that natively and Jamf does it through integration. If the evidence is Apple-specific configuration depth, the reverse.

Get that requirement in writing from whoever owns it, security or compliance rather than IT. Device management decisions made on an assumed requirement tend to over-buy, and the person who actually owns the obligation can usually tell you in one sentence what evidence they need to produce and to whom.

Price the migration, not just the licence. Every device gets unenrolled and re-enrolled. Work out what that means for your remote staff before you commit to a date, because that is the part that slips.

A tactic that makes this considerably less painful: migrate new hires first. Every machine issued after the switchover date arrives on the new platform with no user involvement whatsoever, and you work backwards through the existing fleet at whatever pace people cooperate. The tail gets longer and the disruption gets much smaller, which is usually the right trade.

Six Scenarios and What Each One Points To

Mac-primary, high stakes

More than half the fleet is Apple and the organisation has compliance obligations. Jamf, and the depth will be used rather than decorative. Start from the published $12.50 per Mac per month bundle and treat the sales conversation as negotiation rather than discovery.

The tell that this is genuinely your situation is that somebody outside IT is asking for device evidence on a schedule. Once an auditor, a customer security questionnaire or an insurer is involved, the depth stops being a nice-to-have and starts being the thing you are buying.

Microsoft shop with a design team

Forty Macs inside three hundred Windows machines. Intune, almost certainly, because the licences exist and the Mac compromises are real but tolerable at that ratio.

The failure mode here is the design team itself. Creative staff tend to be the most Mac-literate people in the building and the quickest to notice a management experience that lags. Involve them in the trial rather than presenting a decision, because their cooperation during enrollment is worth more than the feature they will complain about.

Mac-primary, no Mac admin

Apple fleet, nobody who writes configuration profiles. Neither of these first. Look at Iru, formerly Kandji, whose pre-built automation does the work Jamf expects you to script.

Genuinely mixed, roughly even

A hard case and the one where running both is most defensible. The alternative is accepting a compromise on one platform, and at an even split that compromise affects half your estate.

Before committing to two platforms, price the third option honestly: a cross-platform suite that is second-best at both. Hexnode publishes per-device pricing and covers Apple, Windows and Android from one console, and for some evenly split fleets a single adequate tool genuinely beats two excellent ones with a reconciliation problem between them.

Regulated, conditional access required

Device compliance must gate resource access. Intune does this natively through Entra ID. Jamf can achieve it through integration, which works and adds a dependency.

Weigh that dependency properly rather than dismissing it. An integration between two vendors is one more thing that can break during an incident, one more support boundary to argue across, and one more item in a vendor risk assessment. None of that makes it wrong, and all of it belongs in the decision.

Post-acquisition, two platforms inherited

Pick based on which migration is smaller, not which platform is better. Moving 40 devices is a project. Moving 400 is a programme, and the better product rarely justifies the difference.

The exception is when the smaller fleet is the one with the compliance obligation. If the 40 devices are the ones subject to a customer security schedule and the 400 are not, the smaller migration may be the one you cannot afford to get wrong, and that reverses the arithmetic.

The Decision Table

Situation Scale Setup Primary Pain Recommended Starting Point
Mac-primary, compliance stakes 150+ Any Apple depth and evidence Jamf Pro
Microsoft estate, Mac minority Any Any Already paying for Intune Microsoft Intune
Apple fleet, no Mac admin 50 to 200 Distributed Setup time per hire Iru (formerly Kandji)
Even split, both platforms matter 200+ Mixed Compromise either way Run both, deliberately
Conditional access mandated Any Microsoft identity Device-gated access Microsoft Intune
Small Apple fleet, tight budget Under 30 Any Nothing managed Mosyle free tier
Inherited two platforms Any Post-acquisition Two of everything Whichever migration is smaller

Most organisations sit in the first two rows, and the Mac percentage tells you which.

The third row is the one most often mis-assigned. Teams with an Apple-primary fleet and no Apple administrator reach for Jamf because it is the name they know, when the honest answer is a platform built to need less expertise. Choosing Jamf and then not staffing it produces the worst outcome available: enterprise cost, basic configuration.

Apple Business Is Required Either Way

Worth saying plainly, because it gets missed in this comparison specifically.

One naming change first, because it is recent enough to cause confusion. Apple retired Apple Business Manager, Apple Business Essentials and Apple Business Connect on 14 April 2026 and replaced all three with a single free platform called Apple Business, available in more than 200 countries and regions. Vendor onboarding guides and internal runbooks that still say Apple Business Manager mean this.

The change is more than cosmetic. Apple Business now includes Apple's own built-in mobile device management at no cost, with Blueprints for configuring groups, device settings and apps. For a small Apple fleet with straightforward requirements that is worth trying before paying for anything, because it may be enough on its own. It does not remove the case for Jamf or Intune once you need policy depth, third-party patch management or the conditional access tie-in, but it does move the point at which paying becomes necessary.

Both platforms depend on Apple Business for proper Apple enrollment. Intune does not avoid it by being Microsoft. Without Apple Business, automated device enrollment is unavailable and you are relying on users installing a profile they could decline.

This surprises Microsoft-first teams more than anyone, because the rest of the Intune setup lives entirely inside Microsoft's own admin surfaces. The Apple portion does not, and it cannot, since the enrollment capability belongs to Apple rather than to whichever platform is talking to it.

Setting it up means verifying a domain, deciding how it federates with your identity provider, and linking your hardware resellers. The federation decision matters more than it looks: federating means people sign in to Apple services with their work account, which also captures existing personal Apple IDs using a company email address. Those users get prompted to change theirs, and if nobody warned them you get a wave of tickets.

And the purchasing rule applies regardless of platform. Devices must be bought through Apple or an enrolled reseller to appear in automated enrollment. A Mac bought retail or on a company card in an emergency cannot be added later, under either Jamf or Intune.

Audit how your organisation actually buys hardware before you choose anything, because this rule is procedural rather than technical and no platform can work around it. The emergency purchase is the usual culprit: a laptop dies, a manager buys a replacement locally to keep somebody working, and that machine sits permanently outside automated enrollment. One is an annoyance. A pattern of them creates a second tier in your fleet that your enrollment numbers cannot explain.

Running Both, Honestly

Plenty of organisations run Jamf for Apple and Intune for Windows, and it is a legitimate answer rather than a failure to decide.

The case for it is simple. Each platform manages the hardware it was built for, nobody accepts a compromise, and the administrators work in the tools they know. For an even split across a large fleet, that is often cheaper in practice than the productivity cost of the wrong tool on half the estate.

The case against is maintenance. Two consoles means two sets of policies, two compliance reports to reconcile, two renewal conversations, and a standing requirement that somebody understands both. It also doubles the places an auditor can find an inconsistency.

The practical test for whether dual-platform is working is whether anybody can answer a compliance question across the whole fleet in one go. If producing an encryption report means exporting from two systems and reconciling them in a spreadsheet, you do not have two platforms, you have two silos and a manual process between them. That is survivable at a hundred devices and genuinely risky at a thousand.

Jamf integrates with Intune for device compliance, so a Mac managed by Jamf can report compliance state into Microsoft's conditional access. That integration is the main reason the dual-platform approach is practical rather than merely tolerable, and it is worth evaluating specifically if you are leaning that way.

Evaluate it on real devices rather than on the documentation. Compliance integrations between vendors are the kind of thing that works exactly as described until a particular policy or a particular identity configuration is involved, and the only way to know is to enroll a machine, fail it deliberately, and watch whether access is actually blocked.

Where Teams Get This Decision Wrong

The mistake How it shows up What fixes it
Comparing features, not fleets A forty-row grid that settles nothing Count Macs as a percentage first
Not checking existing licences Buying what you already own Open the Microsoft admin centre
Ignoring who administers it Capability bought and never used Name the person before the platform
Assuming Intune skips Apple Business Enrollment users can decline Set up Apple Business regardless
Treating dual-platform as failure Forcing a bad fit on half the fleet Price running both properly
Underestimating re-enrollment A date that slips by weeks Plan the user communication first

The second row is the most common and the most expensive. Organisations buy Apple management while already holding Microsoft 365 E3 licences that include Intune Plan 1 capability, because nobody checked. That is a real recurring cost paid for nothing.

The sixth row is the one that damages trust rather than budget. A migration date announced before the user communication is written produces a week of confused people being asked to run commands on their own laptops with no context. The technical work is straightforward. The part that goes wrong is social, and it is entirely preventable by writing the message first.

What an MDM Will Never Tell You

Both platforms share a limitation that neither markets, and it catches teams during offboarding.

An MDM knows about devices that check in. It cannot see the MacBook in a drawer since March, the laptop bought on expenses and never registered, or whether a leaver's machine came back. Remote wipe is a command in a queue that executes the next time the device contacts the server, so for a laptop nobody has seen in four months it waits, possibly forever, while the compliance report shows the wipe as pending.

That is an asset management gap rather than an MDM shortcoming, and the fix is a register alongside the MDM rather than a better MDM. Platforms like RemoAsset sit on that side, handling procurement, delivery and physical retrieval, with MDM enrollment happening on delivery. Neither category replaces the other, and a team whose real problem is device recovery will deploy either Jamf or Intune perfectly and find the problem untouched.

The diagnostic is one question. Ask what broke last quarter. If a machine was misconfigured, unpatched or missing encryption, that is an MDM problem and this comparison is the right one to be having. If a laptop never came back, or an audit turned up hardware nobody had recorded, neither Jamf nor Intune addresses it and the budget should go elsewhere.

What to Establish Before You Commit

Artefact Why it matters When
Mac count as a share of fleet The single decisive number Before any vendor call
Current Microsoft licence position Intune may already be paid for Before any vendor call
Named administrator and their background Decides which platform is operable Before shortlisting
Compliance and conditional access needs Separates native from integrated Before demos
Apple Business status Required by both Before deployment
Re-enrollment communication plan The part that slips Before setting a date

The second row takes ten minutes and changes the economics of the entire comparison. Do it first.

Questions to Ask Before You Commit

On fleet. What share of our devices are Apple? A bad answer is roughly.

On licensing. Do we already have Intune capability? A bad answer is probably not.

On Mac depth. Which macOS features released this year are not supported? A bad answer is none.

On enrollment. Does this need Apple Business? The only correct answer is yes.

On migration. What must each employee do personally? A bad answer is nothing.

On exit. How do we export policies if we switch? A bad answer is vague.

What Getting This Wrong Costs

The first cost is buying what you already own. Microsoft 365 E3 at $39.00 per user per month includes Intune Plan 1 capability, and organisations holding those licences still buy separate Apple management without checking. For a 200-person company that is a meaningful annual line item purchased for no gain.

The second is capability you cannot operate. Jamf is the strongest Apple platform available and it rewards an administrator who knows the ecosystem. Without that person it becomes a console somebody logs into quarterly, with the depth unused and the licence renewed anyway.

The third shows up at the audit. Running two platforms without deciding to is different from running two deliberately. The accidental version has two policy sets that drifted apart, two compliance reports nobody reconciles, and an inconsistency waiting to be found. The deliberate version has an owner for each and a documented reason.

There is a fourth cost that only appears at renewal, and it is the one that catches growing companies. Per-user and per-device pricing diverge as a fleet matures, because phones and tablets accumulate faster than headcount does. Model both platforms at your projected size rather than today's, and get both figures in writing, because the number you will actually be paying is the second one.

So ask the diagnostic question before the demos. Is this a platform-depth problem, a licensing problem, or an operator problem? Those have three different answers and only one of them is a feature comparison.

Most teams arriving at this comparison have the second or third and describe it as the first, because depth is the thing vendors talk about and licensing and staffing are internal. Separating them before anybody books a call is the most useful hour in the process, and it frequently ends the search without a demo at all.

When You Are Ready to Decide

Start by counting. Macs as a percentage of total devices, and your current Microsoft licence position. Those two numbers resolve most of this comparison before anybody books a call, and they take an afternoon to establish properly.

Then name the administrator and ask which ecosystem they already know. That answer is worth more than any feature row, because both platforms are good and neither is usable by somebody fighting the interface.

If the honest answer is that nobody knows either ecosystem well, that is useful information rather than a dead end. It points away from Jamf's depth and towards a platform with pre-built automation, and it means the budget conversation should include training or a managed service rather than only licences.

Then trial the leading candidate on real devices rather than spares. Enroll a machine belonging to somebody who will complain, push a policy they will notice, and try to undo it. What separates these products in daily use is how that loop feels, and no comparison grid captures it.

And give the trial to the person who will own it, not to whoever is most curious. The useful signal is whether your actual administrator can get a policy out without reading documentation for an hour, because that is what the next three years look like.

HROpsLab publishes independent comparison work across HR and IT tooling. We sell nothing, we take no vendor money, and we publish no paid placements. Every price here came from the vendor's own pricing page, and where a vendor publishes nothing, we say so rather than estimating.


Frequently Asked Questions

Is Jamf better than Intune?

For managing Apple devices, yes, and that is the narrow and correct version of the answer. Jamf has the deepest Apple management available and the largest body of community knowledge in the category, so if Macs are your primary platform it will serve you better. For managing a mixed estate where Windows dominates and Macs are a minority, Intune is usually the right choice despite being second on Apple, because it manages everything from one console and you may already own it.

Does Microsoft 365 include Intune?

Microsoft 365 E3 at $39.00 per user per month and E5 at $60.00 both include Intune Plan 1 capability, which is why so many organisations already hold it without realising. Plan 2 is available standalone at $4.00 per user per month for teams that want the advanced capabilities without the wider suite. Checking your current licence position takes ten minutes in the admin centre and frequently changes the entire comparison.

Can Jamf and Intune work together?

Yes, and this is the standard approach for organisations running both. Jamf integrates with Intune for device compliance, so a Mac managed by Jamf can report its compliance state into Microsoft's conditional access and be granted or denied resource access accordingly. That integration is what makes a dual-platform setup practical rather than merely tolerable, and it is worth evaluating specifically if your fleet is close to an even split.

How much does Jamf Pro cost?

Jamf now publishes list pricing, though not for Jamf Pro on its own. The Jamf for Mac plan is $12.50 per macOS device per month, billed annually, with a 25-device minimum, and it bundles Jamf Pro with Jamf Connect and Jamf Protect. Jamf for Mobile is $5.75 per mobile device per month on the same terms, and Jamf Now, aimed at smaller teams, starts at $4 per device per month. Because those are list figures for bundles rather than for the management product alone, a standalone Jamf Pro quote still comes from a sales conversation, so ask for the figure at your projected device count as well as today's, because this is a category where growth costs surprise people.

Is Intune good enough for Macs?

Capable, and visibly second to its Windows support. The core surface is there including enrollment through Apple Business, configuration profiles, compliance policies, FileVault enforcement and app deployment, which covers what most organisations with a Mac minority actually need. What lags is timing and depth, with new macOS capabilities arriving later than in the Apple specialists, and Mac-literate staff tend to notice within a quarter.

Do we need Apple Business with Intune?

Yes, and choosing Microsoft does not avoid it. Apple Business is the free platform that replaced Apple Business Manager, Apple Business Essentials and Apple Business Connect on 14 April 2026, and it is what enables automated device enrollment, where a Mac enrolls itself during first setup rather than relying on somebody installing a profile they could decline. It also handles volume app purchasing and now includes Apple's own built-in device management, which does not replace Intune for a mixed fleet but is worth knowing about. Set it up before deploying either platform, because verifying a domain and settling the identity federation question both involve waiting on other people and routinely add a week.

What if our fleet is split evenly?

That is the hardest case and the one where running both platforms is most defensible, because accepting a compromise affects half your estate rather than a minority of it. Weigh the licence and maintenance cost of two consoles against the productivity cost of the weaker tool on half your devices, and factor in whether you have administrators comfortable in both ecosystems. Plenty of organisations at an even split run Jamf for Apple and Intune for Windows deliberately, with the compliance integration connecting them.

How disruptive is switching between them?

More than vendors suggest, because every device must be unenrolled from the old platform and enrolled into the new one. In an office that is a trolley and an afternoon. Across a distributed fleet it means asking each person to act on their own laptop, the stragglers take weeks, and you run two consoles until the last one completes. A useful tactic is migrating new hires first so every machine issued after the switchover arrives on the new platform with no user involvement, then working backwards through the existing fleet.

Share on X Share on LinkedIn

What to do next?

Explore More Articles

Dig deeper into HR Ops strategy, tools, and workflows built for real teams.

Browse the blog →
Join the HROpsLab Community

Connect with People Ops practitioners sharing real workflows, tools, and challenges.

Join now →