Updated: October 2026
Windows laptops, a few MacBooks, company iPhones and a drawer of Android scanners rarely arrive in the same year or from the same buyer. Each platform has its own enrolment rules, and each tool on the market is strong on some of them and thin on others. This guide compares MDM solutions for a mixed fleet: what they do, how devices get enrolled, which tools cover which platforms, and how to roll one out without a second migration a year later.
TL;DR
- MDM is the console that talks to management features Apple, Google and Microsoft build into their operating systems. The tool sets policy; the OS enforces it.
- Enrolment decides how much control you get. Company-owned devices should enrol automatically (Windows Autopilot, Apple Automated Device Enrollment, Android zero-touch). Personal devices get a separated work space, not full control.
- Coverage is the first filter. Jamf and Mosyle are Apple-only. Intune, Hexnode, Scalefusion, ManageEngine, NinjaOne, JumpCloud and Iru (formerly Kandji) cover several platforms, each with different depth.
- Microsoft 365 shops usually already own Intune. Apple-heavy teams often pair an Apple specialist with Intune for the rest. Small mixed offices lean toward one cross-platform console.
- Pilot with ten devices per platform, set the five baseline policies first, and plan the migration path before you sign.
What an MDM Solution Does
Mobile device management started with phones, but the same protocol now manages laptops and desktops too. An MDM server sends instructions. The device's own management framework applies them and reports back.
Five jobs come up on every platform. Enrol binds the device to your organization, ideally before the user sees the home screen. Configure pushes settings: passcode rules, Wi-Fi, VPN, email profiles and restrictions. Deliver apps installs, updates and removes work apps and keeps them apart from personal ones. Check compliance reports encryption, OS version and jailbreak or root status, and feeds that into sign-in decisions. Secure or retire locks a lost device, wipes it, or removes only work data when someone leaves.
Everything else a vendor sells is built on those five. When two tools look alike in a demo, ask how each one handles the five on each platform you own. The answers differ more than the feature pages suggest.
MDM vs UEM vs MAM
Three acronyms describe overlapping products, and vendors use them loosely.
MDM manages the whole device. It can wipe it, force encryption and set the lock screen. That's the right level for company-owned hardware.
MAM, mobile application management, manages only the work apps and the data inside them. Nothing is installed at device level. Microsoft's app protection policies are the common example: they can stop a user copying data from Outlook into a personal app without enrolling the phone at all. It's the usual answer for personal phones.
UEM, unified endpoint management, is MDM plus the jobs that used to live in separate tools for desktops: OS update rings, software deployment, patching and inventory, across every platform. Our guide to unified endpoint management covers where UEM ends and an RMM begins.
In practice, the tools in this guide sell themselves as UEM. Treat the label as a claim to test, not a feature.
How Devices Get Enrolled on Each Platform
Enrolment is where a rollout succeeds or stalls. The method decides what you can control later, and each platform has its own.
Windows. Windows Autopilot turns a new PC from the factory image into a business-ready device during first setup. Microsoft's Autopilot overview lists what it handles: joining Microsoft Entra ID, enrolling into MDM automatically, assigning configuration and customising the out-of-box screens. Automatic MDM enrolment needs Microsoft Entra ID P1 or P2 for configuration. Autopilot can also reset and repurpose a device later.
Apple. Automated Device Enrollment (ADE) is the Apple path for company-owned devices. Devices bought through Apple or an authorised reseller appear in Apple Business Manager (Apple's deployment guide now calls it Apple Business) and are assigned to your MDM server. Apple's deployment guide describes the result: devices are configured "from the moment someone removes a device from its box," and a supervised device can't be unenrolled by the user. On a Mac with macOS 14 or later, the MDM can also require FileVault during setup and escrow the recovery key. Our FileVault guide covers that part.
Android. Android Enterprise sets the mode at provisioning. Google's Android Management API docs describe two ownership models: personally owned devices get a work profile, and company-owned devices are either a work profile or fully managed, including dedicated single-app devices. Provisioning methods include zero-touch enrolment, QR codes, NFC and enrolment links. One detail catches teams out: a device offline for 270 consecutive days has to be reprovisioned.
Zero-touch only works on hardware the reseller registered. That came up in this r/sysadmin thread on managing Android tablets, where the practical advice was to buy Android Enterprise Recommended devices and use the zero-touch portal so they enrol into whichever MDM you pick:
The pattern is the same on all three platforms. Automatic enrolment depends on how the device was bought. Fix purchasing first: order through a reseller that registers devices with Autopilot, Apple Business Manager and Android zero-touch, and every new device arrives managed.
MDM Solutions Compared
The table below covers ten tools that come up repeatedly in IT and MSP evaluations. Platform coverage comes from each vendor's own product pages and docs, checked in September 2026. Depth varies: a tool can "support" a platform with a handful of settings or with full parity.
| Tool | Platforms covered | Where it fits | Pricing model |
|---|---|---|---|
| Microsoft Intune | Windows, macOS, iOS/iPadOS, Android, Linux (Ubuntu, RHEL), ChromeOS | Microsoft 365 organizations | Plan 1 bundled in Microsoft 365 plans such as E3 and E5; Plan 2 and Suite add-ons; device-only licences for kiosks |
| Jamf Pro | Mac, iPhone, iPad, Apple TV | Apple-heavy fleets | Per device, quote-based |
| Iru (formerly Kandji) | Mac, iPhone, iPad, Apple TV, Vision Pro, plus Windows and Android | Apple-first teams adding other platforms | Per device, quote-based |
| Mosyle | Apple only | Apple fleets, schools | Per device |
| Hexnode UEM | Windows, macOS, iOS, Android, Linux, ChromeOS, tvOS, visionOS, Fire OS | Mixed fleets, kiosks and rugged devices | Per device, tiered editions |
| ManageEngine MDM Plus | Android, iOS, iPadOS, tvOS, macOS, Windows, ChromeOS | Cost-conscious mixed fleets; cloud or on-premises | Per device; published list prices |
| Scalefusion | Android, iOS/iPadOS, macOS, Windows, Linux, ChromeOS | Mixed fleets, frontline and kiosk devices | Per device, tiered editions |
| NinjaOne MDM | Android, iOS, iPadOS, macOS, Windows, Linux | Teams already on NinjaOne RMM | Quote-based |
| JumpCloud | Windows, Apple, Linux, Android | Teams that want directory, SSO and devices in one place | Per user, tiered |
| Google endpoint management | Android, iOS, plus Windows and other computers | Google Workspace organizations | Included in Workspace and Cloud Identity editions |
A few notes the table can't hold:
Microsoft Intune covers every major desktop and mobile OS, Linux and ChromeOS included. Microsoft sells it mainly inside Microsoft 365 bundles, so the question is often "is Intune enough?" rather than "should we buy it?" Our Intune review covers where it stops for multi-client MSPs.
Jamf Pro and Mosyle are Apple specialists. Jamf describes itself as "complete Apple device management," and Mosyle calls itself "the only Apple Unified Platform." Neither manages Windows or Android, so a mixed fleet needs a second tool. The Apple MDM comparison goes deeper on the Apple-only field.
Iru is the new name for Kandji. Its site says "Kandji's Apple device features are now cross-platform," and lists Windows and Android alongside Apple devices. Expect Apple depth to lead and the newer platforms to trail for a while. Test the Windows side on your own devices before you rely on it.
Hexnode, Scalefusion and ManageEngine are the cross-platform generalists. They go further into kiosk, rugged and frontline devices than the Apple specialists do. ManageEngine publishes list prices: as of 30 September 2026, its cloud edition started at $1.28 per device per month (Standard) and $2.38 (Professional). In the r/sysadmin thread above, one admin found ManageEngine's Android remote control "slow and unresponsive," while another said it was clunky but good enough to keep. Trial the features you'll use daily, not the ones in the demo.
NinjaOne and JumpCloud come at MDM from a neighbouring product. NinjaOne adds mobile management to its RMM console. JumpCloud starts from the directory and adds device management for Windows, Apple, Linux and Android. Both make sense when you already run the parent product.
Google endpoint management is on by default for Workspace customers. Google's admin help describes two levels: basic mobile management with no app to install, and advanced management that requires one and adds device wipe, iOS app management and Android work profiles.
If open source matters, Fleet is worth a look for Apple, Windows and Linux on top of osquery. We covered it in our Fleet MDM review.
What MDM Costs: The Pricing Models
MDM pricing comes in four shapes, and the shape matters more than the headline number.
Per device. Hexnode, Scalefusion, ManageEngine, Mosyle and Jamf price by enrolled device. Kiosks and shared tablets count like laptops. This suits fleets with more devices than people.
Per user. JumpCloud and Microsoft's bundles price by person. One user with a laptop, a phone and a tablet costs the same as one with a single device.
Bundled. Intune Plan 1 arrives with Microsoft 365 plans such as E3 and E5, and Google endpoint management arrives with Workspace. The licence is already paid for. The cost is admin time and the gaps you fill with other tools.
Quote-based. Iru and Jamf mostly quote per deal, and NinjaOne publishes a range ($1.50 to $3.75 per device, October 2026) with the exact rate on a quote. Ask for the price at your device count today and at double that count. Ask about contract terms such as minimums and renewal pricing. Our NinjaOne pricing guide shows how the published range plays out.
Shared devices are the edge case to price separately. Microsoft offers a device-only licence for kiosks, dedicated Android devices and devices enrolled without a user, such as Autopilot self-deploying mode. Its licensing docs list what you give up with it: no app protection policies, no conditional access and no user-based features like email. That's usually fine for a warehouse scanner and wrong for a manager's tablet.
The hidden cost is the second tool. An Apple specialist plus Intune for Windows and Android means two consoles, two policy sets and two places where a leaver's devices need retiring. That can still be the right call. Price the admin hours along with the licences.
Pick by Situation: A Shortlist Table
Start from the fleet you have, not the feature list. This table maps common situations to a short list worth trialling.
| Your situation | Shortlist | Why |
|---|---|---|
| Microsoft 365 E3/E5 or Business Premium, mostly Windows | Intune | Already licensed; conditional access built in |
| Apple is more than half the fleet | Jamf, Mosyle or Iru, plus Intune for Windows | Apple depth first; second tool covers the rest |
| Small mixed office, one admin | Hexnode, Scalefusion, ManageEngine | One console across platforms |
| Android kiosks, scanners or rugged devices | Hexnode, Scalefusion, ManageEngine, Intune (dedicated mode) | Kiosk and zero-touch support |
| Google Workspace shop | Google endpoint management, then a cross-platform tool if gaps remain | Already included |
| Directory and SSO also needed | JumpCloud | Identity and devices in one product |
| MSP managing many clients | Tools with multi-tenant consoles; compare Intune with Lighthouse against RMM-native MDM | Tenant switching is the daily cost |
A Worked Example: 40 Devices, Four Platforms
Here's how the table plays out for an illustrative 40-person firm. The numbers are made up; the reasoning is the part to copy.
The fleet: 22 Windows laptops, 8 MacBooks, 6 company iPhones and 4 Android barcode scanners in the warehouse. Staff also read email on personal phones. The firm already pays for a Microsoft 365 plan that includes Intune Plan 1.
Option one: Intune for everything. The licence is paid for. Windows enrols through Autopilot, Macs and iPhones through Apple Business and ADE, the scanners through Android Enterprise dedicated mode, and personal phones get app protection policies without enrolment. One console, one compliance model, one set of conditional access rules. The trade-off is Mac depth. Intune manages macOS, so check how its recent macOS feature support compares with an Apple specialist before the design team finds out the hard way.
Option two: an Apple specialist plus Intune. Jamf, Mosyle or Iru takes the Macs and iPhones; Intune keeps Windows, Android and personal phones. Apple devices get a tool whose whole focus is Apple, and the Mac-heavy design team gets the self-service app catalogue it asked for. The trade-off is two consoles, two leaver checklists and two licences.
Option three: one cross-platform tool. Hexnode, Scalefusion or ManageEngine covers all four platforms and does well with the warehouse scanners in kiosk mode. The trade-off is the Microsoft 365 licence the firm is already paying for, and conditional access now depends on an integration rather than a native feature.
For this fleet, option one wins on cost and simplicity, and option two wins only if Mac users push back hard. The decision rule is plain. Buy a second tool when a platform's users lose something they need, not because a demo looked better.
Questions to Ask in a Trial
Feature lists look alike. These questions separate tools during a two-week trial:
| Question | Why it matters |
|---|---|
| Does automatic enrolment work with our resellers on every platform? | Manual enrolment doesn't scale past the pilot |
| How fast does it support a new iOS or macOS release? | Apple ships yearly; a slow tool blocks upgrades |
| Can it report compliance into our sign-in provider? | Compliance that doesn't block access is a report nobody reads |
| What does a leaver look like? | Count the clicks to retire every device one person had |
| How are kiosk and shared devices licensed? | Per-user pricing gets awkward for devices nobody owns |
| Can we export policies and device data? | You'll want both if you ever migrate |
| How does it separate clients or sites? | MSPs and multi-site firms live in that screen |
| What breaks when the admin is on holiday? | Look for delegated roles and audit logs |
Policies to Set First
A new MDM with no policies manages nothing. Five baseline policies cover the common risks on every platform:
- Screen lock and passcode. A PIN or password, a short auto-lock, and a wipe or lockout after repeated failed attempts.
- Encryption. BitLocker on Windows, FileVault on Mac. Phones encrypt by default once a passcode is set. Escrow recovery keys to the MDM or your directory.
- OS updates. Update rings or deferral windows so patches land within days, with a small pilot ring first.
- Compliance to sign-in. Mark devices that fail the checks as non-compliant and block them from email and files until fixed. In Microsoft environments this is conditional access: a laptop with BitLocker off shows as non-compliant, and Outlook stops syncing until encryption is back on.
- Lost device. Test remote lock and wipe on each platform before you need them.
Everything else can wait for the second month. Start with 200 settings and you spend weeks debugging your own policies.
Rolling Out MDM Without a Second Migration
Switching MDM later is expensive, because moving a device usually means re-enrolling it. Apple has eased this for its own devices. Its deployment guide says devices on iOS 26, iPadOS 26 or macOS 26 enrolled through Automated Device Enrollment can be assigned to a new MDM with a deadline, and iPhones and iPads can keep their apps and data if the new service delivers the apps first. Windows and Android still mean re-enrolment or a reset. Plan the first rollout with that in mind.
- Inventory. Count devices by platform and ownership. You can't choose coverage without the numbers.
- Fix purchasing. Connect Apple Business Manager, Autopilot registration and Android zero-touch with your resellers before the pilot.
- Pilot. Ten devices per platform, including one owned by the most demanding user in the building.
- Baseline. The five policies above, nothing else.
- Waves. Enrol by department, newest devices first. Replace old devices at refresh rather than hand-enrolling them twice.
- Retire the old tool. Keep it read-only until the last device is moved, then cancel.
Budget a week per wave for questions. The questions are the training.
Common MDM Rollout Mistakes
Watch for five mistakes that cost weeks.
Enrolling by hand. A pilot of ten devices enrolled by a technician feels fine. The same method across 200 devices becomes a month of desk visits, and every device enrolled by hand can often be unenrolled by its user. Get the reseller registration done before the first wave.
Copying a baseline from the internet. Security baselines are useful references, but applying a full one on day one locks out apps nobody tested. Start with the five policies above and add settings one at a time, each with a named reason.
Blocking before reporting. Compliance policies should report for a week before they block. The first report tends to show devices nobody knew about: the reception PC, the old iPad in the meeting room, the laptop a contractor never returned.
Forgetting the leaver. Offboarding is where MDM pays for itself, and it's the step teams test last. Retire a pilot device end to end: remove the user, wipe or release the device, confirm it drops out of every report.
Letting the old tool linger. Two MDMs claiming the same device fight over settings. Move a device, confirm it's healthy in the new tool, then remove it from the old one the same day.
BYOD: What You Can and Can't Manage
Personal devices need a lighter touch, and the platforms enforce it. Android's work profile keeps work apps and data in a separate space the organization manages. Apple's User Enrollment separates managed data and limits what IT can see. App protection policies manage the work apps without enrolling the phone at all.
The practical split looks like this. On a personal phone you can require a PIN for work apps, block copy and paste from work apps into personal ones, and wipe the work data when someone leaves. You can't read personal photos, messages or browsing, and you shouldn't wipe the whole device. That list settles a lot of BYOD objections before they start.
Tell staff in writing what IT can and can't see, and what happens to their data when they leave. Our BYOD policy template has the clauses.
The mixed-platform reality shows up in this r/msp thread. The poster needed Mac and phone management. The answers settled on two tools: Mosyle or Addigy for Apple, Intune for Android, and the RMM for everything else.
Where MDM Ends and RMM Begins
MDM manages configuration through the OS vendor's framework. It's strong at policy, apps and compliance, and weaker at the jobs technicians do all day: remote control, scripting, monitoring and third-party patching on desktops. An RMM covers those.
For MSPs, the extra question is tenants. Intune lives inside each client's Microsoft tenant, so a technician switches tenants or uses Microsoft 365 Lighthouse to see several at once. Tools built for MSPs put every client in one console with per-client policies. Neither is wrong; count how often your team moves between clients in a day before you choose.
A common split is MDM for policy and phones, RMM for Windows and Mac operations. OpenFrame can run a compliance check, such as an encryption or OS version query, as a script across a client's devices and collect the output in one place.
Professor Messer's overview is a good primer to send to a new technician before the pilot starts:
For Apple-heavy teams weighing Jamf against Intune, this walkthrough from Stabilise compares the admin experience side by side:
The Short Version
Pick MDM solutions by coverage first, enrolment second and features third. List your platforms and ownership models, check which tools cover all of them at the depth you need, and fix purchasing so new devices enrol themselves. Start with five policies and ten pilot devices per platform.
If your fleet is mostly Apple, read the Apple MDM comparison next. If you're weighing a desktop-focused tool, start with unified endpoint management.
Content Marketing Lead
Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.
