Enterprise Leader #2 Overall

Iru (formerly Kandji)

Apple-first MDM specialist expanding into Windows and Android post-October 2025 rebrand, with built-in EDR and compliance automation.

Enterprise-custom; no published pricing; industry estimates $4-15/device/month for MDM; EDR/Compliance add-ons increase cost.
Apple-first organisations expanding into Windows and Android, enterprises seeking unified endpoint management with built-in EDR
iOS Android Windows macOS
4.1 Overall Score

Key Takeaways

Who It's For

Iru (formerly Kandji) is designed for apple-first organisations expanding into windows and android, enterprises seeking unified endpoint management with built-in edr. Apple-first MDM specialist expanding into Windows and Android post-October 2025 rebrand, with built-in EDR and compliance automation. The platform offers a contact sales, so you can evaluate it before committing.

Industry-leading Apple management with Managed OS, 120+ one-click restrictions, and DDM support
Built-in EDR with behavioural analysis for macOS and Windows (no third-party tool needed)
No Linux or ChromeOS support — Apple, Windows, and Android only

At a Glance

Best For
Apple-first organisations expanding into Windows and Android, enterprises seeking unified endpoint management with built-in EDR
Setup Complexity
Advanced
Pricing Range
Enterprise-custom; no published pricing; industry estimates $4-15/device/month for MDM; EDR/Compliance add-ons increase cost.
Licensing Model
Per-device/user; unified pricing across platforms; enterprise volume discounts typical but not published.
Top Strength
Industry-leading Apple management with Managed OS, 120+ one-click restrictions, and DDM support
Trial
Contact sales

Buyers Guide

Download the full 2026 comparison spreadsheet with scores, pricing, and feature data for all 13 platforms.

Excel format

Score Breakdown

Scored across 10 categories based on 67 features evaluated per platform.

Avg 4.2 / 5.0
Identity & Directory 4.5
App Management 4.4
Reporting & Visibility 4.3
Remote Actions & Support 4.3
Integration & Extensibility 4.3
Device Configuration 4.3
Targeting & Policy Logic 4.2
Compliance & Security 3.9
Enrollment & Provisioning 3.8
OS Update & Lifecycle 3.7

Pros & Cons

Based on our hands-on evaluation of Iru (formerly Kandji).

Strengths

4
  • Industry-leading Apple management with Managed OS, 120+ one-click restrictions, and DDM support
  • Built-in EDR with behavioural analysis for macOS and Windows (no third-party tool needed)
  • Assignment Maps provide visual, conditional policy logic unique in the market
  • AI-powered compliance automation with adaptive evidence mapping for audit readiness

Limitations

3
  • No Linux or ChromeOS support — Apple, Windows, and Android only
  • Windows and Android features still maturing post-rebrand (less documentation depth)
  • No published pricing — enterprise-custom only, estimated $4-15/device/month
Pain Point Challenge

How Does Your MDM Stack Up?

Wondering how your setup compares to Iru (formerly Kandji)? Take the Pain Point Challenge and find out.

Take the Challenge

Feature Breakdown

Individual feature scores across all 10 categories for Iru (formerly Kandji).

Compare features across platforms

Device Configuration

8 features
5.0 Certificate Management (SCEP/PKI)

Strong SCEP support with AD CS Connector; integrates with Microsoft AD CS, GlobalSign, SecureW2.

4.0 Custom Configuration Profiles

.mobileconfig upload for Apple System Channel; limited Android via third-party app configs.

5.0 Device Restrictions

120+ one-click restrictions for Apple; full Declarative Device Management on iOS 16+; Android/Windows supported.

4.0 Email Profile (Exchange/IMAP)

Custom profiles with global profile variables ($EMAIL) for personalized email configuration.

5.0 Passcode / Password Policy

DDM-based passcode on iOS 16+; configurable gap 0 min to 8 hrs; password change frequency daily to biennially.

2.0 Per-App VPN

iOS per-app VPN via AppConfig supported. No per-app VPN on Android, Windows, or macOS.

4.0 VPN Profile Configuration

Native VPN profiles via MDM; integrates with OpenVPN, NordVPN, Twingate, AWS VPN Client.

5.0 Wi-Fi Profile Configuration

Enterprise Wi-Fi profiles with EAP-TLS support and trusted certificate integration.

Enrollment & Provisioning

8 features
4.0 Android Zero-Touch Enrollment

Added post-Oct 2025 rebrand; supports Google zero-touch provisioning for bulk Android enrollment.

5.0 Apple ADE (Automated Device Enrollment)

Core ADE capability with improved interface; supports Setup Assistant for Mac, iPhone, iPad, Apple TV, Vision Pro.

4.0 Bulk / Staging Enrollment

Leverages ADE, zero-touch, and Knox for bulk provisioning; supports staged rollout with test groups.

4.0 Conditional / Identity-Based Enrollment

Assignment Maps and rules with Azure AD, Google Workspace, Okta integration for identity-driven enrollment.

4.0 Manual / QR Code Enrollment

Universal Enrollment Portal with unique URLs and codes; QR code scanning for Android and iOS.

1.0 Samsung Knox Mobile Enrollment

No Knox ME documentation found. Samsung devices use standard Android zero-touch enrollment.

4.0 User-Initiated Enrollment (BYOD)

Self-service enrollment portal with BYOD blueprints; supports User Enrollment on Apple with privacy separation.

4.0 Windows Autopilot

Windows Autopilot zero-touch provisioning supported with automatic policy and app deployment. Source: iru.com/resources/device-management/windows.

App Management

8 features
4.0 App Blocklisting / Allowlisting

Restrictions profile with blocklist/allowlist; Auto Apps prevents unapproved use; app lock for maximum restriction.

5.0 App Catalog / Enterprise App Store

Self Service app library; 200+ Auto Apps pre-packaged for Mac/Windows; VPP, Google Play distribution.

4.0 App Configuration (Managed App Config)

AppConfig XML dictionaries for app settings; strong iOS support, limited Android/macOS.

5.0 Apple VPP / ABM App Distribution

Full ABM Apps and Books integration; auto-converts unmanaged to managed apps; device-based licensing.

4.0 Managed Google Play Integration

Added post-Oct 2025; Google Play deployment for Android with zero-touch app distribution.

4.0 Mobile Application Management (MAM)

App policy management; full iOS/iPad support, growing Android/Windows; container-based approach.

5.0 Silent App Installation

Auto Apps silently cache and install without user interruption; iOS apps deploy silently via MDM.

4.0 Win32 / LOB App Deployment

Windows Win32/LOB deployment; macOS supports .pkg custom app packages.

Compliance & Security

8 features
5.0 Compliance Policy Engine

AI-powered compliance automation with adaptive evidence mapping; real-time compliance dashboards.

3.0 Data Loss Prevention (DLP)

Third-party DLP integration (SURF Security); Iru EDR provides data protection; strongest on Mac/Windows.

4.0 Encryption Enforcement

FileVault on macOS fully documented. BitLocker referenced in general context but no dedicated support article found. iOS encryption native.

3.0 Geofencing Compliance

iOS Lost Mode with 15-min updates; conditional access geofencing; limited Android/Mac support.

4.0 Jailbreak / Root Detection

iOS jailbreak detection documented. Android root detection confirmed; auto-blocks corporate access for rooted devices. Source: iru.com/resources/device-management/android.

5.0 Remote Wipe (Full Device)

EACS command for Apple; full device wipe for Android/Windows; Return to Service option on Apple.

3.0 Selective / Corporate Wipe

iOS BYOD/User Enrollment separates data; Android work profile; macOS/Windows limited selective wipe.

4.0 Threat Defense Integration (MTD/EDR)

Iru EDR for Mac/Windows with behavioral analysis; iOS/Android via third-party MTD APIs.

OS Update & Lifecycle

6 features
2.0 Android OS Update Control

Visibility into outdated OS versions only; no direct update control. Android updates follow manufacturer schedules. Source: iru.com/resources/device-management/android.

2.0 Firmware / Driver Updates

macOS firmware managed via Apple OS updates. No Windows/Android firmware or driver management.

5.0 iOS/iPadOS Update Management

Managed OS with automatic enforcement or minimum version; supports deferral restrictions and countdown timer.

5.0 macOS Update Management

Flagship Managed OS for macOS; automatic enforcement, beta release control, 30-min countdown before forced install.

4.0 Update Deferral & Scheduling

iOS Software Update Deferral restriction; macOS Managed OS with flexible deferral; Windows configurable periods.

4.0 Windows Update Management

Schedules quiet updates, prompts users, and enforces when needed; supports deferral and staged rollout.

Reporting & Visibility

6 features
3.0 App Usage Analytics

Prism reporting provides app inventory; installed apps per device; analytics more limited than dedicated UEM.

4.0 Audit Logging

Automated auditing for compliance; logs admin actions and device changes; Sumo Logic/SIEM integration.

5.0 Compliance Reporting

AI-powered compliance automation; adaptive evidence mapping; audit-ready evidence collection.

4.0 Custom Report Builder

Prism reports with custom filtering and detailed reporting across device status, compliance, ops.

5.0 Device Inventory Dashboard

Consolidated device view with quick filtering, exports, and searchable attributes.

5.0 Real-Time Device Status

Real-time compliance dashboards; device check-in status; real-time threat alerts from EDR.

Remote Actions & Support

6 features
4.0 Custom Script Execution

Custom Scripts Library executes as root on macOS; Windows agent supports scripts; iOS/Android limited.

5.0 Remote Device Restart

Restart with configurable countdown (default 30 min); force restart option; all platforms supported.

5.0 Remote Lock

Lock Device generates 6-digit PIN; supported on all platforms; immediate execution.

4.0 Remote Screen View / Share

Native VNC on macOS; iOS Lost Mode location view; third-party integrations (TeamViewer, Splashtop).

3.0 Remote Terminal / Shell

Kandji Agent CLI on macOS; Custom Script Library for root-level execution; Windows limited.

5.0 Remote Wipe (Action)

Erase Device action; EACS for Apple, Return to Service option; full wipe for Android/Windows.

Targeting & Policy Logic

5 features
5.0 Device-Type Assignment

Assignment Rules target by device type (iPhone, iPad, Mac, Windows, Android).

4.0 Dynamic / Smart Groups

Tags with Assignment Rules and Maps enable conditional policy targeting; visual conditional logic.

3.0 Geo / Network-Based Targeting

Geofencing via conditional access; location-based assignment; network-based targeting through policy conditions.

5.0 Tag-Based Targeting

Multi-value tag system used with Assignment Rules/Maps; organization-wide targeting mechanism.

4.0 User-Based Assignment

Directory integration enables centralized user-based assignment with automatic device assignment.

Identity & Directory

6 features
5.0 Azure AD / Entra ID Integration

SCIM sync for user/group objects; native OIDC and SAML SSO; Passport for Mac login.

4.0 Conditional Access Policies

Assignment Maps provide conditional logic; Azure AD conditional access integration; location/network targeting.

5.0 Google Workspace Directory

Full SCIM directory integration with 4-hour sync cycles; Passport supports Google Workspace SAML auth.

5.0 Okta / Third-Party IdP

SAML integration with Okta; Passport OIDC; 23 Okta Workflows connector cards for automation.

3.0 On-Premises Active Directory

AD CS Connector for certificates; no direct LDAP; primarily through cloud directory sync.

5.0 SAML / OIDC SSO

Both SAML and OIDC supported for console and Passport; native Azure AD, Okta, Google integrations.

Integration & Extensibility

6 features
4.0 Automation Workflows

150+ pre-built automations; Okta Workflows with 23 connector cards; Assignment Rules/Maps for policy automation.

4.0 Custom Connector / Plugin Framework

REST API enables custom connectors; Unified.to and Workato pre-built integration patterns.

5.0 REST API

Comprehensive REST API (10,000 req/hr rate limit); full CRUD on devices and policies.

5.0 ServiceNow / ITSM Integration

Native ServiceNow integration via Import Set API; real-time device inventory sync; CMDB mapping.

4.0 SIEM Integration

Sumo Logic integration; audit logs exportable for SIEM ingestion; EDR threat event logging.

4.0 Webhooks / Event Notifications

Webhooks for instant updates; event-driven automation with third-party platform integration.

Alternatives to Consider

Other platforms to evaluate alongside Iru (formerly Kandji).

Jamf Pro

Enterprise Leader
4.0

The gold standard for Apple device management with unmatched macOS and iOS feature depth.

iOSmacOS
Read Review

Omnissa Workspace ONE

Enterprise Leader
4.6

The broadest cross-platform UEM with enterprise-grade automation and real-time compliance.

iOSAndroidWindowsmacOS +2
Read Review

Microsoft Intune

Strong Contender
3.9

The Microsoft ecosystem's native MDM, deeply integrated with Entra ID and Microsoft 365.

iOSAndroidWindowsmacOS +2
Read Review

User Reviews

Be the first to review Iru (formerly Kandji)

Your feedback helps other IT professionals make better decisions.

Write a Review

Share your experience with Iru (formerly Kandji)

Never shared publicly

Rating *

Ready to decide?

Compare Iru (formerly Kandji) Head-to-Head

See how Iru (formerly Kandji) stacks up against Jamf Pro, Workspace ONE, Intune in a detailed side-by-side comparison.