Jamf Pro and Microsoft Intune both enrol and configure Macs using Apple’s MDM protocol, but Jamf is an Apple-only platform and Intune is one console covering Windows, macOS, iOS and Android. Both are legitimate choices. The comparison is not about which is better in the abstract, it is about how many Macs you have, what you already pay for, and how much control you actually need.
Anyone who tells you one is universally superior is selling something. What follows is what each genuinely does and does not do on macOS as it stands today.
Disclosure before you read any further: we are a Jamf partner and we are also a Microsoft partner, and we run Macs under both products. Being partnered on both sides is what makes this a comparison rather than a pitch, and below you will find the cases where we tell clients not to buy Jamf.
Intune on macOS is far better than its reputation
Intune’s Mac support was thin for years and the reputation has outlasted the reality. It now covers most of what a normal business needs.
Automated Device Enrolment through Apple Business, formerly Apple Business Manager works properly. Compliance policies feed Conditional Access. The settings catalog is now Microsoft’s recommended way to build macOS policy, and it covers both Apple’s declarative configurations such as software update settings and passcode, and traditional payloads such as FileVault, firewall, Gatekeeper and system extensions. Anything Microsoft has not ingested can be uploaded as a custom mobileconfig file. FileVault management with personal recovery key escrow and rotation is supported, as is macOS LAPS for the managed local admin account on Automated Device Enrolment machines. Shell scripts run. App deployment covers volume purchased apps, signed and unsigned packages, disk images and Microsoft’s own applications.
Platform SSO with Microsoft Entra ID is generally available and is genuinely good, particularly the Secure Enclave backed Platform Credential method that Microsoft recommends. It requires macOS 14 or later in practice, the Microsoft Authenticator app, and Company Portal 5.2404.0 or later deployed before you target users.
If you run Microsoft 365 Business Premium, E3 or E5, you already own Intune. For a business with a handful of Macs beside a Windows estate, that is a strong argument on its own.
What Intune genuinely cannot do on macOS
These are the concrete gaps, each of which Microsoft documents.
Endpoint Privilege Management is Windows only. This matters more than anything else on this list. EPM is a headline component of the Intune Suite, and its documentation carries an explicit Windows applicability banner with supported file types of exe, msi and ps1. If you are being sold the Intune Suite as the answer to just-in-time admin rights on Macs, the answer is that it does not do that. Privilege elevation on macOS with Intune means scripting it yourself.
There is no Self Service equivalent. Company Portal can offer apps for a user to install on demand. It cannot publish a policy or a script for a user to run on demand. Jamf Self Service can publish policies, scripts, configuration profiles, apps, patch policies and bookmarks. For a fleet where users need to trigger a printer install, a VPN repair or a re-enrolment themselves, this is the difference between a self-service tile and a support ticket.
There are no policy triggers. Jamf documents six triggers including startup, login, network state change, enrolment complete, recurring check-in and custom events invoked on demand. Intune has no equivalent. Scripts run against the agent’s check-in cycle.
Remediations are Windows only. The detect-and-fix pattern that Windows admins rely on does not exist for macOS in Intune.
Deep device inventory is Windows only. Microsoft’s device inventory feature states that it supports Windows devices only, and that on Apple devices properties are simply collected automatically. You get what the MDM protocol returns and no control over the depth.
Third-party application patching is thin. Enterprise App Management, Microsoft’s automated patching service for non-Microsoft software, is documented as curated Win32 apps. There is no macOS equivalent. Jamf ships both App Installers, where Jamf sources and signs the packages, and classic patch management where you supply the package. Note that App Installers is a Jamf Cloud capability, so it is off the table for on-premises Jamf.
Check-in latency is real. Microsoft documents that newly enrolled Macs check in every 15 minutes for an hour and then roughly every eight hours, with maintenance syncs throttled to one every 6.5 hours. Jamf’s default recurring check-in is every 15 minutes. If you push a policy change on a Friday afternoon, Jamf lands it that afternoon and Intune may not land it until Monday.
Script behaviour is constrained. Microsoft documents scripts under 1 MB, a 60-minute timeout after which the run is marked failed, root execution by default with an option to run as the signed-in user, and an agent check-in every eight hours. Reporting is lossy in a way that trips people up: a recurring script only reports status the first time it runs, and thereafter only when the status changes.
One correction to a common claim: Intune does have an extension attribute analogue in custom attributes for macOS, which run a shell script every eight hours and return a string, integer or date, capped at 20 KB. The real gap is not that they do not exist. It is that they are reporting-only. Jamf extension attributes feed directly into smart group criteria and profile variables. Intune custom attributes cannot be used as dynamic group or filter criteria, so you can see the value but you cannot target on it.
There is more detail in a closer look at Intune on macOS.
What Jamf gives you for the extra licence
Jamf’s advantage is not a longer feature list. It is depth in three specific places.
Smart groups. Jamf evaluates group membership against the entire inventory record, including hardware, operating system, security state, disk encryption, installed applications, package receipts, local user accounts, certificates and your own extension attributes, with nested and-or logic. That is a different order of targeting precision than Entra dynamic groups plus assignment filters.
Self Service and triggers together. Publishing a self-healing action that a user can run on demand, or that fires on login or network change, removes a whole class of support ticket. This is the capability Mac-heavy shops miss most when they move to Intune.
Same-day operating system support. Jamf publishes an annual claim of same-day support for new Apple releases, most recently marking 14 consecutive years. It is a real track record and it matters when a design team updates on release day. Be clear about what it is though: it appears in press releases, not in a service level agreement, with no remedy attached. Treat it as a strong indicator, not a contractual guarantee.
The product line itself is worth getting right, because it changed recently. Jamf’s current plans are Jamf for Mac and Jamf for Mobile, each bundling Jamf Pro with Jamf Connect and Jamf Protect, plus Jamf for K-12 for schools. Jamf Now still exists and has not been discontinued, but it is now positioned for organisations under 25 employees. Jamf Trust is the end-user client app rather than a separate licence.
Licensing structure, and why we are not quoting prices
The two vendors behave completely differently here, and that difference is itself useful information.
Intune is licensed per user and is included in Microsoft 365 E3, E5, F1 and F3, Enterprise Mobility and Security E3 and E5, and Microsoft 365 Business Premium. Above that base sit Intune Plan 2 and the Intune Suite as additive add-ons, along with standalone add-ons such as Remote Help and Endpoint Privilege Management. Microsoft publishes list pricing openly on its Australian pricing page. For most Australian SMBs the marginal cost of managing Macs with Intune is zero, because the licence is already bought.
Jamf publishes no list price for any current plan. Every option is a contact request. The one published figure is a free tier in Jamf Now for up to three devices. Jamf for Mac and Jamf for Mobile are Jamf Cloud only, so on-premises customers are on a different footing. Beyond that, minimum quantities, contract terms and volume tiers are not published, which means the real answer for your fleet size can only come from a quote.
We are not going to print dollar figures here, because Microsoft’s change without notice and Jamf’s are not published at all. What you can rely on is the shape: Intune is usually already paid for, Jamf is always an additional line item, and the question is whether the capability gap justifies it.
Twenty Macs versus two hundred
Around 20 Macs, mostly Windows business, already on Business Premium or E3. Use Intune. Jamf is over-specified at this size and we say so on the call. The licence is sunk, one console is genuinely easier to run, compliance flows into Conditional Access without an integration, and the gaps are survivable at that scale because you can absorb the occasional manual task. Do not buy the Intune Suite expecting privilege management on those Macs.
Around 200 Macs, or Macs as the primary platform. Use Jamf. At that scale the missing self-service, the eight-hour policy latency and the absent third-party patching stop being inconveniences and start being headcount. Smart groups alone will save more time than the licence costs.
The middle, roughly 50 to 100 Macs. This is where it is a genuine judgement call, and the deciding factor is usually the software estate rather than the device count. A team running standard productivity software is fine on Intune. A creative or engineering team with a long tail of third-party applications that all need patching is not, because that is precisely the gap.
If you already pay for Intune, you can run both
This is the option most people do not know exists. Jamf can manage the Macs while Intune owns compliance and Conditional Access, through Microsoft’s partner compliance management integration.
Get the history right, because it changed. The old Conditional Access partner integration is retired. Jamf announced the deprecation with Microsoft and the end of support date was extended to 31 January 2025. The current path is the Device Compliance integration, configured under Device Compliance in Jamf Pro and added as a compliance partner in Intune. Some Microsoft pages still cite the older date, which is a documentation lag rather than a live option.
Practical constraints worth knowing before you commit: the integration supports Entra user groups only, and compliance policies targeted at device groups will not apply. Users must register through Jamf Self Service rather than by launching Company Portal directly. And Jamf-managed devices do not appear in Intune’s device list, so your asset view stays split.
It is more moving parts, and it is the right answer surprisingly often in a genuinely mixed Windows, Mac and Google environment, where the Macs are a meaningful population but the identity and compliance story has to stay in one place.
Our recommendation, and what it costs you
For most Australian SMBs between 10 and 200 staff with fewer than about 50 Macs, start with Intune. You already own it, one console is materially easier to operate and document, and compliance integration is native rather than bolted on.
The trade-off is real and you should accept it knowingly: slower policy delivery, no self-service for users, no on-demand or triggered actions, manual third-party patching, and no privilege management on macOS regardless of which Intune plan you buy. If those constraints start generating tickets rather than mild annoyance, that is your signal to move, and it is a signal that arrives at a fleet size rather than a date.
Whichever you choose, the platform is the smaller half of the problem. Apple’s own rules on supervision, user approval, bootstrap tokens and privacy consent apply identically to both, and they are what actually determine whether your fleet is controlled. That ground is covered in how Mac enrolment and policy actually work and sits alongside your wider approach to endpoint security across the fleet. We run Mac fleets under management alongside Windows, and we are a member of the Apple Consultants Network, Apple’s programme of independent technology partners specialising in Apple solutions for small and medium-sized businesses. That is why this comes out as a fleet-size answer rather than a brand preference.
If you want this decided on evidence rather than a vendor pitch, the useful next step is a short review of your Mac count, your existing Microsoft licensing and the applications those Macs actually run. Call 1300 028 324 or get in touch at https://techassist.au/contact/, and we will give you a straight recommendation, including when the answer is to keep using what you already pay for. We have been doing Mac support in Melbourne for over 20 years.