Jamf, Intune, or Mosyle? The differences that actually decide it

Every MDM demo looks the same. The real differences show up three weeks in — in how each one does smart groups, scripting, identity, and compliance. A field comparison of the three I run most, with the specifics that matter.

jamfintunemosylemdm

Every MDM looks fine in a demo. They all enroll a Mac, push a profile, install an app, and show you a green checkmark. The differences that matter don’t show up until three weeks in, when you’re trying to do something specific and the tool either has an elegant answer or makes you fight it.

Here’s where Jamf, Intune, and Mosyle actually diverge — the three I deploy most, compared on the things you’ll hit, not the things on the feature matrix.

Smart groups and targeting

This is the single biggest day-to-day difference.

Jamf is built around smart groups and extension attributes: membership that recomputes from inventory, and the ability to script any fact about a Mac into that inventory and target on it. “Every Mac on Sonoma, in the Design department, missing our security agent” is a five-minute smart group. Almost every Jamf workflow — scoping, Self Service, patch policies — hangs off this. Nothing else in Apple management matches its expressiveness.

Intune gives you dynamic Entra groups and the Settings Catalog. They’re fine for “all macOS devices” or “everyone in this Entra group,” but there’s no real equivalent to an extension attribute — you can’t trivially invent a custom inventory fact and scope on it. You bend your logic to fit what’s there.

Mosyle has dynamic device groups that cover the common cases well, but the deeper you go into custom, inventory-driven targeting, the more you feel the ceiling compared to Jamf.

Scripting and automation

Jamf runs scripts as policies, with parameters, scoping, and Self Service triggers, and exposes a deep Pro API plus webhooks. If you want to automate the platform itself, it’s all reachable.

Intune runs shell scripts through its agent as root, but the model is thinner — limited script slots historically, coarse scheduling, and far less of the platform exposed for orchestration. It’s enough for a baseline, not for elaborate workflows.

Mosyle surprises people here: its automation and built-in workflows (custom commands, scripts, and the way it chains them) are genuinely good for the price, and often cover an SMB’s whole need.

Identity and security

Jamf has the deepest stack: Jamf Connect for identity at the login window and password sync to your IdP, and Jamf Protect for real endpoint security and telemetry. Integrated, mature, and priced accordingly.

Intune’s entire reason to exist on Apple is compliance feeding Conditional Access: device state flows into Entra and gates access to Microsoft 365. If your security model is built on Conditional Access, that loop is the deciding feature — and nothing replicates it as cleanly.

Mosyle bundles a lot — its own identity, encryption, and endpoint-security pieces — into the subscription. The bundle is strong value; individually the pieces aren’t as deep as Jamf’s specialized tools.

The questions that actually decide it

Strip away the feature lists and it comes down to three:

What does the rest of your stack look like?

If you live in Microsoft 365 — Entra for identity, Conditional Access, a Windows fleet beside the Macs — Intune earns a serious look. You already pay for it, your security team already knows the console, and compliance flows straight into access. If you’re Apple-first or on Google Workspace, Intune’s advantages shrink fast and its weaker macOS story starts to show.

How much depth do you need?

Jamf is the deepest Apple platform, full stop — complex smart groups, sophisticated deployment, Jamf Connect, Jamf Protect. The trade-off is cost and needing someone who actually knows it. Mosyle covers the common 80% at a fraction of the price with genuinely good automation; for a 30-person shop that needs solid baselines and zero-touch, it’s often the rational pick.

Who owns it after it’s set up?

A perfectly configured Jamf instance that nobody on the team understands is shelf-ware within a year. The platform has to match the people who’ll run it — and that constraint quietly overrides the other two more often than anyone likes to admit.

The short version

  • Microsoft-centric org, mixed Windows + Mac fleet → Intune
  • Apple-heavy org that needs depth and polish → Jamf
  • Smaller team, value-focused, Apple-only → Mosyle

There are exceptions to all three, and the “right” answer changes the moment one of those three questions changes. If your experience points somewhere different, the comments are open — I’d genuinely like to hear where these break down for you.

Comments

    No account needed · comments are moderated