Jamf vs Intune for managing Apple devices in India
A 140-person product firm in Powai asked me to choose an MDM for their 48 Macs. They had already chosen one. Nobody in the room knew it yet.

Jamf vs Intune is the wrong question until you have two numbers. What share of your fleet is Apple, and how many people on your team write scripts. Intune manages Macs properly now, and it is already included in Microsoft 365 Business Premium, E3 and E5, so most Indian buyers already own it. Jamf goes deeper on Apple than Intune can, and it costs real money on top of the licence you already pay for.
Under roughly 40 percent Mac with a small IT team, Intune usually wins. Mac-majority estate with a scripter on staff, Jamf earns its bill.
The question arrived framed as Jamf or Intune. That is already the wrong question.
Powai, a Tuesday in October, a 140-person product design and engineering firm. 48 Macs on the design and engineering floor, 92 Windows laptops across sales, finance and operations, one head of IT, one junior admin, and a security questionnaire from a European client sitting open on the screen. The questionnaire is what started this. It asked how they enforce disk encryption on every endpoint, and the honest answer was that nobody knew for the Macs.
I am Karthik. I have run this evaluation for four mixed fleets now. This is the one where my first recommendation was wrong, so it is the one worth writing down.
One disclosure before anything else. We sell and support Microsoft licensing and we sell Apple hardware, so read this knowing that. We make money either way, which is exactly why we can be straight with you.
What Intune actually does to a Mac now
Start with the thing most people are wrong about, because the folklore here is five years stale.
Intune enrols Macs through Automated Device Enrollment tied to Apple Business, the same path any Apple-first tool uses. Software updates moved to Apple’s declarative framework, so Intune declares a target version with a deferral and an enforcement deadline, and the Mac installs it and reports back. Microsoft has also committed publicly to day-zero support for new Apple operating systems, which was not true a few years ago and is worth updating your mental model for.
Then the part that decided the Powai room. Intune’s macOS compliance policy checks a fixed list. Microsoft’s own documentation covers system integrity protection, minimum and maximum OS version, password rules, firewall, disk encryption and Gatekeeper. Six things. Custom compliance scripts, the escape hatch you would use to check anything else, are available for Windows and Linux and not for Apple platforms.
Six checks answered the European questionnaire. Encryption was on the list. Bas, that was the whole emergency.
And the money question had already been answered by an invoice they were paying. Intune Plan 1 lists at ₹665 per user per month on microsoft.com, and it is included at no extra cost in Microsoft 365 Business Premium, E3, E5 and Enterprise Mobility plus Security.* They were on Business Premium. Another vendor had quoted them the standalone Plan 1 price as a fresh line item three months earlier. That is the most common way Indian mid-market buyers overpay for MDM, and it takes one look at the licence page to catch. We walk clients through that check as part of our Intune deployment practice before anyone signs anything.
Open your Microsoft 365 admin centre and look at the licence you are already buying. If it says Business Premium, E3, E5 or EMS, core Intune device management is inside it. You are not buying MDM. You are switching it on.
What Jamf sees that Intune cannot
Now walk the other floor, because the Jamf case is real and I do not want to flatten it.
Jamf sells Apple management as three lines now. Jamf for Mac, which bundles Jamf Pro, Connect and Protect for macOS. Jamf for Mobile for iOS, iPadOS and the rest. And Jamf Now for organisations under 25 employees. The plan comparison sits in Jamf’s published product documentation if you want the feature grid.
The depth is not marketing. Jamf argues, in its own published comparison against Intune, that six compliance settings is a short checklist rather than a security posture. Jamf can assess whether XProtect malware signatures are current, whether Recovery Lock is set on Apple silicon, how a Mac scores against the CIS macOS benchmark, whether a specific certificate is installed. It is a competitor making the argument, so weigh it accordingly. I checked the six-setting claim against Microsoft’s documentation and the claim holds.
Then Extension Attributes and Smart Groups, which is where Jamf admins live. You can query any value on a Mac, turn it into an attribute, and group devices on it. Nothing in Intune replicates that on Apple.
Pricing is the part Indian buyers find hardest. Jamf publishes in US dollars and points you to a local reseller for a rupee quote. Public trackers put Jamf for Mac around USD 12.50 per device per month with a 25-device minimum, and Jamf Now around USD 4.* Treat those as the shape of a quote you are about to receive.
Why my first recommendation was wrong
My first draft said run both. It is a legitimate architecture, it is common in large mixed estates, and it goes like this: Jamf manages the Macs at depth, Jamf reports Mac compliance into Microsoft Entra, and Conditional Access enforces across the whole fleet from one identity plane. Clean on a slide. I have drawn it on whiteboards.
Two conversations changed my mind, and neither was about features.
The first was with the junior admin. I asked what he scripts. He said he does not, the person who did left in 2024, and the shared scripts folder still has that person’s name on it. Jamf’s advantage is an operator advantage. Hand it to a team with no operator and you have bought a deeper console that nobody drives. This is the same reason we put an MDM engineer on payroll rather than a ticket queue behind our device lifecycle management work. The console is the cheap half.
The second was arithmetic. 48 Macs at roughly USD 12.50 a month lands near ₹6 lakh a year at current rates, on top of licences already paid for. Matlab, that is most of a junior systems administrator’s salary. And a systems administrator would have closed the real gap, because the real gap was not a missing setting. Nobody was opening the compliance report. Achha, the console had been sitting there for eleven months telling them things.
Which is the corrective pair I keep coming back to. What that firm needed was a person who reads the report every Monday, not a console with more checks in it.
The math: Jamf vs Intune, line by line
This is the table I now draw before any mixed-fleet MDM decision. It arrives here, after both walks, because the walks are what make the rows mean anything.
| The question | Microsoft Intune | Jamf |
|---|---|---|
| What you pay on top of Microsoft 365 | Nothing on Business Premium, E3, E5 or EMS. Plan 1 lists at ₹665 per user per month standalone* | A separate per-device subscription. Jamf for Mac tracks around USD 12.50 per device per month with a 25-device minimum* |
| macOS compliance depth | Six settings: OS version, password, disk encryption, system integrity protection, firewall, Gatekeeper | CIS benchmark scoring, XProtect signature currency, Recovery Lock, certificate and process checks |
| Custom compliance scripts | Windows and Linux only. Apple platforms excluded | Extension Attributes on any value you can query on the device |
| Windows in the same console | Yes, one compliance model across the whole fleet | No. Apple, plus Android on the mobile plan |
| New Apple OS releases | Public day-zero support commitment from Microsoft | Strong, documented at launch |
| Software updates | Declarative policies, macOS 14 and later. Legacy policies covering macOS 12 to 15 are ending | Declarative updates from Jamf Pro 11.8 onward |
| Conditional Access to company data | Native. Same stack, same identity plane | Reports Mac compliance into Entra so Conditional Access still works |
| Who you need on staff | An admin who already runs your Microsoft tenant | Someone who writes and maintains scripts, and stays |
Two rows carry most rooms. The staffing row, because it is the one nobody puts in the evaluation matrix and the one that decides whether either tool works. And the top row, because half the Indian buyers I meet are being quoted for something already sitting inside their licence.
What I told the head of IT
Intune for the whole fleet. Both platforms, one compliance model, one Conditional Access story, no new invoice.
Then two conditions, because a recommendation without a review date is just an opinion.
First, a named owner for the compliance report and a fifteen-minute slot every Monday morning. A person and a calendar entry. When a Mac shows red two weeks running, it goes to the head of IT with a date attached.
Second, a written trigger to revisit Jamf. Any one of these reopens the file. Mac share crossing half the fleet, a client questionnaire asking for CIS benchmark evidence on macOS, or a new hire whose job description includes scripting Macs. It sits in their IT plan with a review date on it, so the decision expires instead of hardening into policy.
The DPDP Act matters here in a way people underrate. The penalty ceiling for failing reasonable security safeguards is ₹250 crore, and an estate where nobody can say which endpoints had encryption enforced last quarter is exactly the estate that question gets asked about later. The audit trail is the part of the fleet that testifies. That is the same reason we keep device records under our device lifecycle management practice rather than in whatever the MDM happened to export that month.
If you are running this evaluation yourself
Five things, in the order I would do them.
Convert your Mac count into a percentage before anything else. 48 sounds like a lot until you set it beside 92. Under 40 percent Apple, the single-console argument usually wins on total effort.
Read your Microsoft licence before you read any vendor deck. Business Premium, E3, E5 and EMS already carry core Intune. Thoda boring, saves lakhs.
Ask who scripts. If the answer is nobody, or the answer is a person who left, Jamf’s best features are not available to you at any price.
Write down the exact compliance evidence a client or auditor has asked you for. Six settings answers many questionnaires. CIS benchmark scoring on macOS does not come out of Intune, and you should know which one you are being asked for.
Check the Apple Business side before blaming the MDM. Half the enrolment failures we get called about are a supplier number that was never linked, not a tool that cannot manage Macs. We wrote the full sequence in our Apple Business setup guide for Indian companies. If you are earlier than that in the process, how to choose an MDM in India is the better starting point.
What to take away
- Fleet share decides more than features. Under about 40 percent Mac, one console and one compliance model usually beat a deeper Apple tool.
- You may already own Intune. Core device management is included in Microsoft 365 Business Premium, E3, E5 and EMS. Check the licence before accepting a quote.
- Six settings is the real Intune limit on macOS. OS version, password, disk encryption, system integrity protection, firewall, Gatekeeper. Custom compliance scripts do not cover Apple.
- Jamf’s depth needs an operator. Extension Attributes and Smart Groups are the product. Without someone who scripts, you are paying for reach you cannot use.
- The hybrid is real but it is two bills. Jamf manages Macs, Entra takes the compliance signal, Conditional Access enforces. Valid design, not a default.
- Nobody reading the report is the actual gap. A named owner and a Monday slot fixes more than a console upgrade does.
Questions the head of IT asked me that week
Is Jamf better than Intune for managing Macs?
On Apple depth, yes. Jamf assesses far more than Intune’s six macOS compliance settings, supports scripted Extension Attributes, and gives Mac admins automation Intune does not offer. Better for your company is a different question. If Macs are a minority of your fleet, if you are already paying for Microsoft 365 Business Premium or E3, and if nobody on your team writes scripts, Intune usually delivers more actual security per rupee because it is the tool your team will operate. Depth you cannot drive is not depth.
Do I pay extra for Intune if I already have Microsoft 365 Business Premium?
No. Intune Plan 1, which covers core device management for Mac, iPhone, iPad, Windows and Android, is included in Microsoft 365 Business Premium, E3, E5, F1, F3 and Enterprise Mobility plus Security. Plan 1 lists separately at ₹665 per user per month on microsoft.com, and that standalone price is what buyers get quoted when the reseller has not checked their tenant. Plan 2 and the Intune Suite are genuine add-ons for advanced capabilities. Ask which one you are being sold before you sign.
Can I run Jamf and Intune together?
Yes, and in larger mixed estates it is common. Jamf manages the Macs at depth and reports Mac device compliance into Microsoft Entra, so Conditional Access policies still evaluate Macs correctly alongside Windows. You get best-in-class on each platform and you pay two subscriptions plus the operational cost of two consoles. It works well for organisations with a dedicated Mac administrator. It works badly for a two-person IT team, because the second console needs an owner and rarely gets one.
How many Macs before Jamf is worth paying for?
Count share rather than headcount. The pattern we see in Indian mid-market estates is that Jamf earns its bill once Macs pass roughly half the fleet, or once someone starts asking for CIS macOS benchmark evidence, or once you employ a person whose job includes scripting Macs. A design studio with 60 Macs and one scripter has a stronger case than a services firm with 120 Macs and none. Jamf for Mac also carries a 25-device minimum, which sets a floor on the smallest sensible deployment.
Does Intune manage iPhones and iPads for Indian companies?
Yes, through Apple Business with Automated Device Enrollment for company-owned devices, and through user enrolment for personal phones under a BYOD policy. The company-owned path gives you supervision, a controlled setup experience and non-removable management. The BYOD path deliberately gives you much less, including no remote wipe of the whole device, which is a conversation worth having with your data protection officer before you promise an auditor anything about phones.
Deciding between Jamf and Intune this quarter?
Send us your fleet split, your Microsoft licence type, and the compliance evidence a client has asked you for. We will tell you which of the two your situation actually needs, and whether you are already paying for it. If the answer is stay where you are and switch on what you own, we will say that. We have written that quote more than once. 200+ Indian businesses work with Sirius Star from Vashi, Navi Mumbai. Response within 24 working hours.
Six months on, all 140 devices sit in one console and the Monday report has an owner. Nobody on the design floor noticed anything changed, which was the goal, pakka. What I still think about is those eleven months. The console had been listing unencrypted Macs the whole time, correctly, to nobody. Every MDM argument I sit through is really an argument about who opens the report.
One page. Your fleet split, your licence position, your compliance evidence and your scripting capacity, scored, with the threshold at which Jamf starts paying for itself. Fill it in before your next vendor call.
Send me the decision worksheet
* Prices are list prices at the time of writing and move with vendor updates, currency and volume. Microsoft publishes Intune pricing in rupees on microsoft.com. Jamf publishes in US dollars and quotes Indian buyers through authorised resellers, so confirm both against a current written quote before you budget.






