Software · Ranked comparison · 7 tools

Best MDM Software, Starting With the One You May Already Own

Seven platforms, one 40 point rubric, every subscore published. Microsoft says to check your existing license first, and after that the billing unit decides the invoice more than the feature list does.

By Marko Ristic, Editor Pricing verified Sep 10, 2026 No paid placement
7platforms scored, every subscore published
4 of 7publish a complete price list
2 of 7manage Apple devices and nothing else
2.4xthe device count per person in a normal office, which decides the unit
Our verdict

Check what you already hold before buying anything: Microsoft states that advanced Intune capabilities are included in Microsoft 365 E3 and E5. For an Apple estate, Jamf is the deepest and publishes its whole price list, while Kandji matches it on automation and publishes nothing.

For a workforce carrying several devices each, JumpCloud bills per user and the arithmetic changes completely. For kiosks, shared hardware or a tight budget, Scalefusion and Hexnode both start near $2 a device with published tiers.

  • Check first, and often already owned: Microsoft Intune
  • Best for Apple, and it publishes the price: Jamf
  • Best when people carry several devices: JumpCloud
  • Cheapest published entry, and best for kiosks: Scalefusion
  • Two of the seven publish no price at all
How this ranking is paid for

We do not accept payment for placement. Scores come from a published 40-point rubric, applied to vendor pricing and product pages read at the source on September 10, 2026; vendors can dispute a fact but not a score. How we rank software · Affiliate disclosure

The rankingComparison table

ToolBest forPricing modelStarts atScore
Microsoft Intune logoMicrosoft IntuneCheck this firstAnyone already on Microsoft 365 E3 or E5Per userIncluded in M365 E3 and E58.9
Jamf logoJamfBest for AppleEstates that are mostly or entirely ApplePer device$12.50 / Mac / mo8.8
JumpCloud logoJumpCloudBest when people have several devicesWorkforces where one person carries three devicesPer user$9 / user / mo8.1
Scalefusion logoScalefusionKiosks, shared devices and tight budgetsPer device$2 / device / mo7.6
Hexnode logoHexnodeSmall businesses that want a price and a trial todayPer device$2.20 / device / mo7.4
ManageEngine Mobile Device Manager Plus logoManageEngine Mobile Device Manager PlusEstates with an odd mix of hardwareQuote onlyQuote only7.3
Kandji logoKandjiApple estates that want automation over configurationQuote onlyNot published7.1

Score is out of 10, from the 40 point rubric below, and every subscore is published with it. Prices were read at each vendor’s own pricing page on September 10, 2026 and carry that date.

MDM, UEM, MAM: one shelf, three signs

Before the table is useful, the word. This page is filed under MDM because mdm software is what most people search for, and about half the products on it are sold as something else. Somebody hunting the best mdm software and somebody hunting unified endpoint management are shopping the same shelf.

ManageEngine, whose Endpoint Central is ranked below, defines the newer term outright: Unified Endpoint Management (UEM) is a way to manage and secure all endpoints in an enterprise, including smartphones, tablets, laptops, desktops, and IoT devices, from a single console.

Its own supported list runs Windows, ChromeOS, Android, Linux, iOS, iPadOS, macOS and tvOS, across desktops, servers, tablets, rugged devices and IoT.

Microsoft covers almost the same ground and will not use the word. Intune supports Android, iOS and iPadOS, Linux, macOS, tvOS, visionOS and Windows, and Microsoft calls it a cloud-based endpoint management service. Its overview page does not contain the phrase unified endpoint management anywhere.

What it does define is the two modes: mobile device management, where the device is enrolled and managed whole, and mobile application management, where only the work apps and the data inside them are managed and the rest of the device is left alone.

The practical reading. MDM is the enrollment and policy layer, and it is the thing every product here does. UEM is the same job once it also covers desktops and servers, which most of these now do, so it is a claim about scope rather than a different product category.

MAM is the mode you want for a device somebody else owns, and it is a feature inside these products rather than an alternative to them.

Which matters when you are comparing quotes, because a vendor selling UEM and a vendor selling MDM may be quoting the same work at different prices, and a vendor selling MAM is quoting less of it.

First, check whether you already own one

The most useful sentence about this category is on Microsoft’s pricing page rather than in any comparison of it: most organizations should first check their existing Microsoft 365 E3 or E5 license.

Advanced Intune capabilities are included in both, and a business paying $39.00 a user a month for E3 is already paying for device management whether or not anybody has switched it on.

That is worth ten minutes before any of the rest of this page. If the answer is yes, the question changes from which MDM to buy into whether the one you own is missing something you need, which is a much cheaper question to answer.

Then the billing unit, which decides the bill more than the features do

This is the category where per user and per device pricing pull hardest apart, because the ratio of people to devices is nothing like one to one any more. A hundred office workers can easily carry two hundred and fifty devices between them once phones and tablets are counted.

ToolUnit100 people, 250 devicesGive everyone one more device
JumpCloudPer user$10,800 a year on Device ManagementNo change
Microsoft IntunePer userIncluded if you hold E3 or E5No change
HexnodePer device$9,600 a year at the $3.20 tierAdds about $3,840 a year
ScalefusionPer device$10,500 a year at the $3.50 tierAdds about $4,200 a year
JamfPer device$25,350 a year at list, all AppleAdds about $6,900 a year
KandjiNot publishedCannot be calculatedUnknown
ManageEnginePer device, by quoteCannot be calculatedUnknown

Read the last column rather than the third one. Per device pricing is a bet that your device count stays flat, and device counts do not stay flat.

The reverse case is just as real: a warehouse of two hundred shared scanners used by thirty staff is the cheapest possible per device estate and the most expensive way to buy per user licensing. Work out which of those two you are before you shortlist anything.

And the platform mix, which quietly removes half the list

Two of the seven manage Apple devices and nothing else. That is not a weakness, it is a specialization, and it is the fastest way to shorten this page for your own situation.

ToolWindowsmacOSiOS and AndroidUnusual hardware
Microsoft IntuneYesYesYesLinux
ManageEngineYesYesYesTVs, rugged, Chrome OS
HexnodeYesYesYesUnified endpoint scope
ScalefusionYesYesYesKiosks and shared devices
JumpCloudYesYesYesIdentity-led rather than device-led
JamfNoYesApple, plus Android on mobilevisionOS, watchOS, tvOS
KandjiNoYesAppleApple only

If the estate is mixed, the bottom two rows are out as a single answer however good they are, and plenty of organizations run one of them alongside something else rather than instead of it.

MethodHow we picked

Forty points across six criteria. Enrollment and management depth is the core job: which platforms, how devices get enrolled, and how far policy reaches once they are. Security and compliance is the half that decides whether a device out of policy loses access to anything, which is where the products separate most.

Automation is what happens without an administrator in front of it. Pricing clarity is whether a buyer can find out the price. Scale and support are what the vendor documents rather than what it implies.

Every subscore is printed in each tool’s section, so a reader weighting these differently can rebuild the ranking. An Apple-only organization should discount the platform breadth that holds Jamf to 8 out of 10 and read it as the top entry, which is the correct answer for that reader.

Prices come from each vendor’s own pricing page with the date, capabilities from their own product pages. Where a vendor publishes nothing, the page says so and scores the silence, because a price kept behind a form is a fact about the product.

What the security and compliance points actually buy

Eight of the forty points sit here, and behind the phrase there is one mechanism. A compliance policy is a set of rules the device is measured against: a minimum operating system version, not jailbroken or rooted, encryption on, a passcode of a stated shape. The device then reports a status.

Microsoft documents exactly that for Intune. Compliance policies are rules used to evaluate the configuration of managed devices, and the examples it gives are a minimum operating system version, not being jailbroken or rooted, and being at or under a threat level reported by integrated threat software.

What separates the products is what happens next. Microsoft lists actions for noncompliance that include marking the device noncompliant, emailing the user about it, remotely locking the device, and retiring it, which removes the device from Intune management and removes all company data from it.

The strongest version of that acts on access rather than on the device. Microsoft states that Conditional Access can use a compliance result to grant or block access to email and other organization resources. Scalefusion sells the same shape: zero trust access to devices and apps driven by its own compliance signals.

The rest of the field describes the work in its own words. Hexnode lists compliance management, geofencing policies, BitLocker management and remote device wipe. Scalefusion lists passcode enforcement, automated endpoint compliance with remediation, and remote wipe or factory reset. Jamf sells compliance benchmarks built on industry security baselines.

Remote actions, which is the part you will actually use

The day mdm software earns its money is the day a laptop goes missing. What matters then is the list of commands you can send to a device you cannot touch, and that list varies by platform more than by vendor, because the operating system decides what is possible.

Microsoft publishes the list per platform. On Windows it includes locate device, remote lock, BitLocker key rotation, collect diagnostics, a Defender Antivirus quick or full scan, Autopilot reset, Fresh Start, and delete, which removes the device from management and removes company data. Two prerequisites apply: enrolled, and online.

That pair is the honest limit of every product here. A remote wipe reaches a device that is enrolled and connected. A phone switched off in the back of a taxi is managed by nothing until it comes back, which is the argument for encryption and a short passcode timeout doing the work first.

Jamf describes its equivalent as remote security commands: managing settings and configurations and restricting malicious software without user interaction. Hexnode and Scalefusion both publish remote wipe of their own.

So the commands themselves are close to universal, and comparing them line by line is wasted effort. What differs is how many devices you can send one to at once, and whether the action can hang off a rule rather than off somebody remembering to press it.

Enrollment, the ten point criterion nobody demonstrates

Enrollment carries the most points on this rubric and gets the least attention in a demonstration, which always starts after it. What matters is that the device somebody is already carrying ends up managed, and the routes differ sharply between a phone the company bought and a phone the person owns.

Microsoft documents the Android side as named modes: personally owned with a work profile for BYOD, corporate owned with a work profile where a work device is also approved for personal use, fully managed for work only, and dedicated for kiosk and single use hardware.

It also documents zero-touch enrollment for bulk provisioning, where corporate owned devices are prepared in advance and enroll themselves as fully managed the first time somebody switches them on. Android hardware without Google Mobile Services takes the Android Open Source Project route instead, userless or user associated.

On the Apple side the equivalent is automated device enrollment. Devices bought through Apple Business Manager or Apple School Manager apply your settings, support supervision, and enroll without anybody touching them, with Setup Assistant walking the user through it. Apple Configurator covers hardware you already have.

For a phone somebody else owns, Microsoft describes Apple User Enrollment, which keeps managed apps and data on a separate volume away from personal data, and Apple Device Enrollment, which gives more control over configuration in exchange for taking more of the device.

This is the section to carry into a sales call. Ask which of those routes a product supports for the hardware already in the building, because the best mdm software for you is whichever one can enroll what you already own. Then ask what happens to a device enrolled somewhere else today.

That second question is the migration, and it is where fleets get stuck.

What the scores are made of

40 points across 6 criteria, applied to vendor pricing and product pages read at the source on September 10, 2026.

10Enrollment and management depth
8Security and compliance
7Automation

Microsoft Intune

Anyone already on Microsoft 365 E3 or E5 · Check this first
8.9out of 10
UnitPer user
Included inMicrosoft 365 E3 and E5
Microsoft 365 E3$39.00 per user per month, paid yearly
Add-ons if not on E3 or E5$2.00 to $5.00 per user per month

Start here, and not because it is the best product. Start here because there is a real chance you are already paying for it.

Microsoft puts the point on its own pricing page more bluntly than any comparison would dare: most organizations should first check their existing Microsoft 365 E3 or E5 license. Advanced Intune capabilities are now included in both, and the page says so at the top.

That reframes the shopping. If your business runs Microsoft 365 E3 at $39.00 per user per month or E5 at $60.00, the endpoint management is in the box, and the question is not which MDM to buy but whether the one you own is short of anything.

For organizations that are not on E3 or E5, the advanced pieces are sold as add-ons on top of Intune Plan 1: Remote Help at $3.50 per user per month, Endpoint Privilege Management at $3.00, Advanced Analytics at $5.00, Enterprise Application Management at $2.00 and Cloud PKI at $2.00, all paid yearly.

On capability it earns its place anyway. It covers Windows, macOS, iOS, iPadOS, Android and Linux, and it is the only product here whose compliance state feeds directly into the identity system deciding whether a device gets to open your email.

That join between device compliance and Conditional Access is what the eight security points are for, and nothing else in this ranking has it natively.

The pricing score is held to 3 because the figures come with a qualifier Microsoft prints under every one of them: prices may vary based on your Microsoft agreement.

A published number you cannot rely on is better than no number and worse than a price list. The full breakdown, including the plan that has no price at all and the device-only license for kiosks, is on the Intune pricing page.

Where it wins

  • Very likely already included in a Microsoft 365 E3 or E5 subscription you pay for today
  • Device compliance feeds Conditional Access directly, which nothing else here does natively
  • Covers Windows, macOS, iOS, iPadOS, Android and Linux from one console
  • Advanced capabilities are itemized and separately priced rather than bundled invisibly

Where it loses

  • Every published figure carries "prices may vary based on your Microsoft agreement"
  • Weakest of the group on Apple-specific management against Jamf and Kandji
  • The licensing map across E3, E5, Plan 1, Plan 2 and the Suite takes real effort to read
  • If you are not already a Microsoft shop, this is a large platform to adopt for device management

How Microsoft Intune scores, criterion by criterion

Enrollment and management depth9 / 10
Security and compliance8 / 8
Automation6.5 / 7
Pricing clarity3 / 5
Scale5 / 5
Support4 / 5

Microsoft Intune pricing, verified September 10, 2026

What you buyPriceAnnualNotes
Microsoft 365 E3$39.00 per user / moPaid yearlyAdvanced Intune capabilities included. $30.45 without Teams
Microsoft 365 E5$60.00 per user / moPaid yearlyIncludes everything in E3. $51.45 without Teams
Remote Help add-on$3.50 per user / moPaid yearlyFor organizations not on E3 or E5
Advanced Analytics add-on$5.00 per user / moPaid yearlyCloud PKI and Enterprise App Management are $2.00 each
Visit websiteWe may earn a commission. It does not affect the score.

Jamf

Estates that are mostly or entirely Apple · Best for Apple
8.8out of 10
UnitPer device
Mac$12.50 per device per month, billed annually
Mobile$5.75 per device per month, billed annually
Minimum25 devices, or Jamf Now under 25 employees

Jamf publishes its whole price list, which puts it ahead of half this category before a single feature is compared, and the list is unusually honest about what it contains.

Jamf for Mac is $12.50 per macOS device per month billed annually with a 25 device minimum, and that figure is not MDM alone: it is Jamf Pro, Jamf Connect and Jamf Protect together, which means management, identity and endpoint protection in one line. Jamf for Mobile is $5.75 per device on the same terms and covers iOS, iPadOS, visionOS, watchOS, tvOS and Android.

Below the 25 device floor there is a separate product. Jamf Now starts at $4 per device per month and is aimed at organizations with fewer than 25 employees, which makes it one of the few genuine answers in this ranking to mobile device management for small business rather than an enterprise product with a small tier bolted on.

What holds the enrollment score to 8 out of 10 is not depth, it is reach. Jamf does not manage Windows, and a mixed estate cannot use it as its only tool. Inside Apple it is the reference implementation and has been for two decades. Outside Apple it is not a candidate.

Worth doing the arithmetic before deciding it is expensive. A hundred Macs and a hundred and fifty phones is $25,350 a year at list, against roughly $10,500 on a per device competitor at $3.50.

What you are buying for the difference is Apple depth plus two products that would otherwise be separate purchases. The full breakdown, including what the 25 device minimum does below that size, is on the Jamf pricing page.

Where it wins

  • The complete price list is published, including the minimums and what each bundle contains
  • The Mac price includes Jamf Pro, Jamf Connect and Jamf Protect rather than management alone
  • Jamf Now, from $4 per device, is a real product for organizations under 25 employees
  • Mobile covers iOS, iPadOS, visionOS, watchOS and tvOS, plus Android

Where it loses

  • No Windows management at all, so a mixed estate needs a second tool
  • A 25 device minimum on the main products, which pushes the smallest buyers to Jamf Now
  • The most expensive per device list price in this ranking, by a wide margin
  • Two price points to model, because Macs and mobile devices are billed differently

How Jamf scores, criterion by criterion

Enrollment and management depth8 / 10
Security and compliance7 / 8
Automation6.5 / 7
Pricing clarity5 / 5
Scale4.5 / 5
Support4 / 5

Jamf pricing, verified September 10, 2026

What you buyPriceAnnualNotes
Jamf for Mac$12.50 per device / moBilled annually25 device minimum. Includes Jamf Pro, Connect and Protect
Jamf for Mobile$5.75 per device / moBilled annually25 device minimum. iOS, iPadOS, visionOS, watchOS, tvOS, Android
Jamf NowFrom $4 per device / moPublishedFor organizations with fewer than 25 employees
100 Macs and 150 phones$2,112.50 / mo$25,350 / yrAt list, on the two business products
Visit websiteWe may earn a commission. It does not affect the score.

JumpCloud

Workforces where one person carries three devices · Best when people have several devices
8.1out of 10
UnitPer user, not per device
Device Management$9 per user per month, billed annually
Device Identity Management$13 per user per month
Published capPlatform Essentials stops at 300 users

JumpCloud is the one product in this ranking that bills for the person rather than the thing, and that single decision matters more than most feature comparisons.

Device Management is $9 per user per month billed annually, or $11 monthly. Device Identity Management, which adds identity and multi-factor authentication for the device itself, is $13 or $15. SSO with a password manager sits between them at $11 or $13.

Run the numbers on a company of a hundred people carrying two hundred and fifty devices between them, which is an ordinary modern ratio once you count phones. JumpCloud is $10,800 a year. A per device product at $3.50 is $10,500 for the same company, and at $12.50 it is far more.

Now give everybody a tablet as well: JumpCloud does not move and every per device competitor does. That is the whole argument, and it works in reverse for a warehouse full of shared scanners with three logins.

The product itself comes at device management from the identity direction rather than the mobile one, which is a genuinely different shape and why it scores 7 on the security half.

It is a directory, an SSO provider and a device manager in one, and for a company with no Active Directory and no appetite for one, that combination is the reason to look.

One published limit is worth knowing before you plan around it: the Platform Essentials package stops at 300 users. JumpCloud also prices every feature individually, which is set out on the JumpCloud pricing page.

Where it wins

  • Priced per user, so a workforce carrying several devices each does not pay several times
  • The whole price list is published in both annual and monthly form
  • Directory, single sign-on and device management in one product, without Active Directory
  • The device identity tier ties multi-factor authentication to the device itself

Where it loses

  • Per user pricing is the wrong shape for shared devices, kiosks and scanners
  • Platform Essentials carries a published ceiling of 300 users
  • Less depth on mobile device management specifically than the mobile-first products here
  • Adding SSO or device identity roughly doubles the entry price

How JumpCloud scores, criterion by criterion

Enrollment and management depth7 / 10
Security and compliance7 / 8
Automation6 / 7
Pricing clarity5 / 5
Scale4 / 5
Support3.5 / 5

JumpCloud pricing, verified September 10, 2026

What you buyPriceAnnualNotes
Device Management$9 per user / moBilled annuallyOr $11 billed monthly. Device management and MDM
SSO$11 per user / moBilled annuallySSO and MFA to resources, plus a password manager
Device Identity Management$13 per user / moBilled annuallyAdds identity and MFA for devices
100 users, any device count$900 / mo$10,800 / yrOn Device Management, at the annual rate
Visit websiteWe may earn a commission. It does not affect the score.

Scalefusion

Kiosks, shared devices and tight budgets
7.6out of 10
UnitPer device
Entry$2 per device per month, $24 a year
Top tier$6 per device per month, $72 a year
TiersFour, all published

Scalefusion publishes four tiers and the annual figure for each, which is the most granular price list in this ranking: $2 per device per month at $24 a year, then $3.50 at $42, $5 at $60 and $6 at $72.

There is no quote in that ladder anywhere, and for a buyer trying to model a hundred tablets against a budget, that is worth more than most feature differences.

The product leans toward the device rather than the person, and it shows in what it is good at: kiosks, digital signage, shared devices, rugged hardware and the kind of estate where the device has a job rather than an owner.

If your fleet is fifty tablets bolted to walls, this end of the market is where you should be looking and the per user products are the wrong shape entirely.

It scores lower on the security half than the platforms above it because the identity and compliance story is thinner. There is no equivalent of Conditional Access deciding whether a non-compliant device gets to open corporate email, and that is the capability the eight points exist to measure.

At $2 a device it is also the cheapest published entry point here, and the honest way to read the ladder is that the useful tier for most businesses is not the first one.

Where it wins

  • Four tiers published with both monthly and annual figures, and no quote in the ladder
  • The cheapest published entry price in this ranking at $2 per device per month
  • Built for kiosks, shared devices and rugged hardware rather than only for staff phones
  • Per device billing suits a fleet where devices outnumber the people using them

Where it loses

  • Thinner identity and compliance story than Intune or JumpCloud
  • No conditional access equivalent tying device state to access decisions
  • Per device billing punishes a workforce carrying several devices each
  • The entry tier is unlikely to be the tier you actually need

How Scalefusion scores, criterion by criterion

Enrollment and management depth7.5 / 10
Security and compliance5.5 / 8
Automation5.5 / 7
Pricing clarity5 / 5
Scale3.5 / 5
Support3.5 / 5

Scalefusion pricing, verified September 10, 2026

What you buyPriceAnnualNotes
Essentials tier$2 per device / mo$24 / device / yrThe cheapest published entry point here
Second tier$3.50 per device / mo$42 / device / yrWhere most businesses land
Third tier$5 per device / mo$60 / device / yrPublished, no quote required
Top tier$6 per device / mo$72 / device / yrStill published
Visit websiteWe may earn a commission. It does not affect the score.

Hexnode

Small businesses that want a price and a trial today
7.4out of 10
UnitPer device
Entry$2.20 per device per month
Top published tier$4.70 per device per month
Trial14 days

Hexnode sits in the same part of the market as Scalefusion and competes on the same terms: published per device pricing at $2.20, $3.20 and $4.70 per device per month, with a fourteen day trial on every tier. For a business that wants to know the cost and start testing on the same afternoon, that combination is the product.

It is a unified endpoint management tool rather than a phone manager, so Windows and macOS are in scope alongside the mobile platforms, which is the difference between this and the Apple-only entries here.

For a small business with a mixed pile of laptops and phones and no Microsoft 365 E3 to fall back on, it is one of the more sensible answers on this page.

The scores below the price reflect a smaller product than the top three. The security half is thinner, there is less published evidence of behavior at several thousand devices, and support arrangements are less clearly documented than at Jamf or Microsoft.

None of that is a fault at the size it sells into; it is the reason it does not outrank the platforms.

Where it wins

  • Three tiers published with clear per device figures and no quote required
  • A fourteen day trial on every tier, so evaluation does not need a sales conversation
  • Covers Windows and macOS alongside mobile, unlike the Apple-only tools here
  • Priced within reach of a business managing a few dozen devices

Where it loses

  • Thinner security and compliance depth than Intune, Jamf or JumpCloud
  • Least published evidence here of behavior at several thousand devices
  • Support arrangements are less clearly documented than at the larger vendors
  • Per device billing again, so several devices per person multiplies the bill

How Hexnode scores, criterion by criterion

Enrollment and management depth7 / 10
Security and compliance5.5 / 8
Automation5.5 / 7
Pricing clarity5 / 5
Scale3.5 / 5
Support3 / 5

Hexnode pricing, verified September 10, 2026

What you buyPriceAnnualNotes
Entry tier$2.20 per device / moPublished14 day free trial
Middle tier$3.20 per device / moPublished14 day free trial
Top published tier$4.70 per device / moPublished14 day free trial
250 devices at $3.20$800 / mo$9,600 / yrWorked from the published middle tier
Visit websiteWe may earn a commission. It does not affect the score.

ManageEngine Mobile Device Manager Plus

Estates with an odd mix of hardware
7.3out of 10
UnitPer device, by quote
Operating systemsAndroid, iOS, iPadOS, tvOS, macOS, Windows, Chrome OS
Device typesPhones, tablets, laptops, desktops, TVs, rugged
PriceNot published

ManageEngine publishes the widest coverage list in this ranking and none of the prices. The operating systems named on its own page are Android, iOS, iPadOS, tvOS, macOS, Windows and Chrome OS, and the device types are smartphones, tablets, laptops, desktops, televisions and rugged hardware.

If your estate contains something unusual, this is the entry most likely to already support it.

The feature set is organized the way an administrator thinks rather than the way a marketing page does: device management, app management, security management, email management, content management and containerization, with containerization being the piece that separates corporate and personal data on a device somebody owns themselves. That last one is the BYOD problem and it is named rather than implied.

The pricing score of 1.5 out of 5 is the whole reason it sits here rather than higher. The route to a number is a form asking for device count, technician count and a choice between Standard and Professional editions, and what comes back is a yearly subscription with support included. The editions are published; the money is not.

Where it wins

  • The widest published list of operating systems and device types in this ranking
  • Containerization for separating corporate and personal data is named as a capability
  • Email, content and app management are each treated as their own area rather than one feature
  • Editions and their contents are published even though prices are not

Where it loses

  • No price published anywhere: the route is a form asking device and technician counts
  • Thinner identity and conditional access story than Intune or JumpCloud
  • Belongs to a large product family, so the boundary with Endpoint Central takes reading
  • Nothing published lets a buyer model the cost before talking to sales

How ManageEngine Mobile Device Manager Plus scores, criterion by criterion

Enrollment and management depth8 / 10
Security and compliance6 / 8
Automation5.5 / 7
Pricing clarity1.5 / 5
Scale4 / 5
Support4 / 5

ManageEngine Mobile Device Manager Plus pricing, verified September 10, 2026

What you buyPriceAnnualNotes
Standard editionQuote onlyYearly subscriptionFixed cost per year, support included
Professional editionQuote onlyYearly subscriptionThe editions are published, the prices are not
The quote form asksDevice count, technician countn/aWhich tells you the shape of the bill if not the size
TrialFreeFreeOffered on the product page
Visit websiteWe may earn a commission. It does not affect the score.

Kandji

Apple estates that want automation over configuration
7.1out of 10
UnitNot published
PlatformsApple
StrengthAutomated remediation of device state
PriceRequest a quote, on every tier

Kandji is the modern alternative to Jamf in Apple estates and its pitch is automation rather than configuration: describe the state a device should be in and let the product keep putting it back, instead of building the workflows yourself.

For a small team without a dedicated Apple administrator that is a meaningful difference, and it is why the automation score is the second highest here.

Then the pricing page, which says request a quote on every single tier. Not a starting figure, not a range, not a per device number with conditions attached.

Its direct competitor publishes $12.50 per Mac and $5.75 per mobile device with the minimums stated, which means a buyer comparing the two can price one of them and not the other. That is 1 out of 5 on pricing clarity, the lowest score on this page, and it is a choice the vendor made rather than an oversight.

Everything else about it is competitive. It is Apple only, like Jamf, so the same limit applies: a Windows estate cannot use it as its only tool. Judge it on a trial and a quote, and get the quote before you spend the trial.

The vendor now trades as Iru. Every kandji.io address redirects to iru.com, where the product is presented as Kandji device management under the Iru name, and the pricing page there still says request a quote on every tier. Checked 2026-09-24.

Where it wins

  • Automated remediation keeps devices in a described state rather than requiring built workflows
  • The strongest automation story of the Apple-focused tools here
  • Aimed at teams without a dedicated Apple administrator
  • A trial is available without going through procurement first

Where it loses

  • Every tier on the pricing page says request a quote, with no figure or range at all
  • Its closest competitor publishes a full price list, which makes the silence conspicuous
  • Apple only, so a mixed estate needs a second product
  • Nothing about the cost can be compared to anything else on this page without a sales call

How Kandji scores, criterion by criterion

Enrollment and management depth7.5 / 10
Security and compliance6 / 8
Automation6.5 / 7
Pricing clarity1 / 5
Scale4 / 5
Support3.5 / 5

Kandji pricing, verified September 10, 2026

What you buyPriceAnnualNotes
Every tierRequest a quoteNot publishedNo figure, range or starting price anywhere on the page
PlatformsApple onlyn/aA Windows estate needs a second product
TrialAvailablen/aGet the quote before spending the trial
ComparisonJamf publishes$12.50 and $5.75The direct competitor prices the same job in public
Visit websiteWe may earn a commission. It does not affect the score.

FitWho this ranking is for, and who should skip it

This ranking is for whoever has to enroll and secure the laptops and phones: an in-house IT lead, or a provider doing it across client sites. It assumes somewhere between a couple of dozen and a few thousand devices.

Three shortcuts. If you hold Microsoft 365 E3 or E5, stop and go and look at what you already own before reading further. If your estate is entirely Apple, the real comparison is Jamf against Kandji, and only one of the two will tell you what it costs.

If you are a small business with a mixed pile of hardware and no enterprise agreement, the published per device tiers at Hexnode and Scalefusion start around $2 to $3.20 a device and both offer a trial you can start without a phone call.

Skip this page if what you actually need is to manage servers and workstations for clients with scripts, patching and remote control. That is RMM, a related category with a different shape and its own ranking. The overlap is real and growing, and several products here appear in both conversations, but the buying decisions are not the same one.

Finally, the thing that decides whether any of this works, and no ranking can score it: enrollment. A device that never enrolled is not managed by the best MDM in the world.

Before choosing on features, find out how each candidate handles the devices you already have in people’s hands, because migrating an existing fleet is the part that goes wrong and the part every demonstration starts after.

ChangelogWhat changed in this update

  • First published. Seven platforms scored on the site’s 40 point rubric, with every price read at the vendor’s own pricing page on September 10, 2026 and every subscore published alongside the total.
  • Retitled so the page names its own subject, MDM software, in the title, the h1 and the body, keeping the angle. Added what the security and compliance criterion is measuring, what an MDM compliance policy is and what happens when a device fails one, and the remote action list with its two prerequisites. Read at Microsoft Learn, Jamf, Hexnode and Scalefusion on September 23, 2026. No price on this page changed.

FAQFrequently asked questions

What are the best MDM solutions?

For most organizations, Microsoft Intune, and often because they already own it inside Microsoft 365 E3 or E5. For an Apple estate, Jamf, which publishes its whole price list, or Kandji if you are willing to ask for a quote.

For a workforce carrying several devices each, JumpCloud, which bills per user rather than per device. For kiosks and shared hardware on a budget, Scalefusion or Hexnode.

Do I already have an MDM without knowing it?

Quite possibly. Microsoft states on its own Intune pricing page that most organizations should first check their existing Microsoft 365 E3 or E5 license, because advanced Intune capabilities are included in both. If your business pays for E3 at $39.00 a user a month, device management is already in that bill.

How much does MDM cost per device?

Published entry prices run from about $2 a device a month at Scalefusion and $2.20 at Hexnode up to $12.50 for a Mac at Jamf, where that figure also includes identity and endpoint protection rather than management alone. JumpCloud prices per user instead, at $9 a user a month billed annually. Kandji and ManageEngine publish nothing.

What is the best mobile device management for small business?

If you are under 25 employees and on Apple, Jamf Now starts at $4 a device a month and exists specifically for that size.

For a mixed pile of laptops and phones, Hexnode and Scalefusion both publish per device tiers from about $2 to $3.20 and both offer a trial you can start without talking to anybody. If you already pay for Microsoft 365 Business or Enterprise plans, check what is in them first.

Is per user or per device MDM pricing better?

It depends entirely on your ratio of people to devices. A hundred staff carrying two hundred and fifty devices pay once each on JumpCloud and two and a half times each on any per device product. A warehouse where thirty staff share two hundred scanners is the exact reverse. Count both numbers before you compare any prices.

Which MDM works with Windows and Mac and phones?

Microsoft Intune, ManageEngine Mobile Device Manager Plus, Hexnode, Scalefusion and JumpCloud all cover Windows, macOS and the mobile platforms. Jamf and Kandji are Apple only, so a mixed estate cannot use either as its single tool however good they are at the Apple part.

What is the difference between MDM and UEM?

Mobile device management started as phones and tablets; unified endpoint management is the same idea extended to laptops, desktops and anything else with an operating system. Most products here are sold as one and behave as the other. The concept page on MDM covers enrollment, policy and the BYOD problem in more detail.

Which MDM vendors publish their prices?

Jamf, JumpCloud, Scalefusion and Hexnode publish complete lists. Microsoft publishes figures with a qualifier under each one saying prices may vary based on your Microsoft agreement. Kandji says request a quote on every tier, and ManageEngine routes to a form asking for device and technician counts.

Can MDM manage personal devices people already own?

Yes, and that is the BYOD case, which every product here addresses differently. The capability to look for is containerization, which separates corporate data from personal data on a device somebody else owns, so that a remote wipe removes the company and not the family photographs. ManageEngine names it explicitly as a feature area.

Does Jamf manage Windows?

No. Jamf manages macOS, iOS, iPadOS, visionOS, watchOS and tvOS, plus Android on the mobile product. A Windows estate needs a different tool, and organizations that are mostly Apple with a few PCs commonly run Jamf alongside something else rather than replacing it.

What does a 25 device minimum mean in practice?

Jamf for Mac and Jamf for Mobile both carry one, so a company with ten Macs pays for twenty-five or uses Jamf Now instead, which starts at $4 a device and is aimed at organizations under 25 employees. It is the kind of term that changes the shortlist for a small buyer and rarely appears in a comparison table.

What is a compliance policy in MDM software?

A set of rules the device is measured against, and a status it reports back. Microsoft describes Intune compliance policies as rules used to evaluate the configuration of managed devices, giving a minimum operating system version, not being jailbroken or rooted, and a threat level as its examples.

What happens when a device fails a compliance policy?

Whatever you configured. Microsoft lists actions for noncompliance that include marking the device noncompliant, emailing the user about it, remotely locking the device, and retiring it, which removes it from Intune management and removes all company data. The default action is only to mark it.

Can MDM software wipe a lost phone?

Yes, on two conditions that apply to every product here: the device is enrolled, and it is online to receive the command. A handset switched off in a taxi is reached by nothing until it comes back, which is why encryption and a short passcode timeout matter more than the wipe does.

Can MDM software block email on a device that is out of policy?

That is the useful version of enforcement. Microsoft states that Conditional Access can use the compliance result from Intune to grant or block access to email and other organization resources. Scalefusion describes the same shape as zero trust access driven by its own compliance signals.

Does MDM software manage disk encryption?

On Windows, yes. Hexnode lists BitLocker management among its features, and Microsoft includes BitLocker key rotation among the remote actions available for a Windows device. Encryption enforcement is usually a compliance rule as well, so a device without it reports as noncompliant.

Where do these scores come from?

The 40 point rubric applied to what each vendor publishes: pricing pages, product pages and documentation, read on September 10, 2026 and dated on the page. Every subscore is shown, so the arithmetic behind each total can be checked rather than taken on trust. There is no paid placement.

Not an MSP? Hire one.Compare state-registered managed IT providers in your city and get up to three quotes. We never provide IT ourselves.