OpenFrame Gen1 is Here

Apple devices keep landing in client fleets, and the management question rarely gets answered before the first MacBook shows up. Someone finds Apple Business Manager, sets it up, and assumes device management is covered. It isn't. For a provider running Apple hardware across a dozen client tenants, picking wrong here turns into a support-time problem within a quarter. Here's what separates the options, plus the 2026 Apple change that makes the decision urgent.

TL;DR

  • Apple Business Manager isn't an MDM. It handles enrollment, identity and app licensing, then hands off to a separate MDM that pushes the policy.
  • Multi-tenancy is the dividing line for providers. Addigy is built around it. Jamf, Iru and Mosyle are built around a single organization.
  • 2026 forces the move. Apple is removing legacy MDM software update commands, so declarative device management stops being optional.

Apple Business Manager Doesn't Manage Devices

This is the single most common misread in the category, and it costs providers real hours. Apple Business Manager is free, and it does four jobs: it proves your organization is who it says it is, it links purchased hardware to your account so devices enroll automatically out of the box, it distributes app licenses through Apps and Books, and it issues Managed Apple Accounts for users.

What it does not do is push a configuration profile, enforce FileVault, deploy software, run a script, check compliance, or wipe a lost laptop. Every one of those needs an MDM that you connect to Apple Business Manager. Apple's own deployment documentation describes choosing a device management service as a separate step from setting up Apple Business Manager, because they are separate things.

Two pieces of plumbing sit between them, and both bite providers who skip the detail. Automated Device Enrollment is what makes a Mac supervised and locked to your MDM the moment it's unboxed, and it only works if the reseller or Apple pushed that serial into the right Apple Business Manager account. An APNs certificate signs every command your MDM sends to every managed device, and it expires annually. Miss the renewal and the entire client fleet goes silent until you re-enroll each device by hand.

The ownership question underneath all this decides your exit terms. If Apple Business Manager and the APNs certificate live under your provider account rather than the client's, offboarding that client means re-enrolling every device. If they live under the client's account, you keep delegated access and hand back cleanly. Settle that before the first enrollment, not during the breakup.

The 2026 Change That Forces a Decision Now

Apple has been moving device management toward a declarative model for several years, where the device watches its own state and reports changes rather than waiting for a server to poll it. At WWDC 2026 that shift stopped being a recommendation.

The operational detail that matters: legacy software update mechanisms are being removed with the 2026 OS release. That includes the old MDM update commands, the com.apple.SoftwareUpdate payload, the associated restrictions and the update queries your reporting probably depends on. Any MDM still driving patching that way stops driving patching. If your vendor hasn't shipped declarative software update enforcement, patch compliance across your Apple fleet breaks inside twelve months.

Two smaller changes in the same release land squarely on provider workflows. Apple Business Manager can now enforce enrollment deadlines on eligible devices, which closes the gap where a user delays enrollment indefinitely and nobody notices until an audit. And credentials can be delivered as declarative assets rather than bundled inside a configuration profile, so certificate renewals stop requiring a profile rebuild and the same credential can serve several network configurations.

The good news arrived in the same release cycle. With macOS 26 Tahoe, iOS 26 and iPadOS 26, Apple Business Manager and Apple School Manager support migrating a device to a different device management service without a wipe. No factory reset, no data loss, no shipping laptops back to the office.

That quietly rewrites the buying math. Switching Apple MDM used to mean touching every endpoint, which is exactly why providers stayed on tools they'd outgrown. Migration is now a policy change on supported hardware. If a vendor's pitch leans on how painful leaving would be, that hold is largely gone, and inherited client fleets on someone else's MDM are far cheaper to consolidate than they were last year.

What Multi-Tenancy Means When the Fleet Isn't Yours

Almost every Apple MDM buying guide is written for an IT team managing one organization. Providers have a different problem, and it has four parts.

Tenant isolation is the first. One console, separate client environments, no chance of a policy written for Client A landing on Client B's laptops. Without it, technicians log in and out of separate consoles all day, juggling separate credentials for every client.

Cross-tenant operations are the second. Pushing one baseline to forty environments, or answering "which clients are exposed to this CVE" in one query rather than forty. Per-client reporting and billing is the third, since you need device counts per tenant that reconcile against what you invoice.

Clean offboarding is the fourth, and it's the one that gets skipped. Handing a client their Apple environment back should be a delegation change, not a fleet-wide re-enrollment.

The cost of missing these is measured in minutes, which is why it hides. Addigy's own argument for multi-tenancy is that providers without it spend the day logging in and out of client accounts, tracking separate credentials and switching tabs. Put a number on it: two minutes of context switching, twenty client touches a day, one technician, and you've spent roughly three and a half hours a week on navigation. Across a four-person team that's most of a full-time salary going to tab management.

Only one vendor in this comparison was designed around that model from the start. The rest solve it with reseller portals, partner programs or separate accounts per client, which works at five clients and gets expensive in labor at fifty. If you've been through the same argument on the Windows side, the pattern is identical to the one we covered in NinjaOne vs Intune: the feature list looks fine until you multiply it by tenant count.

Apple MDM Options Compared

ToolPlatform scopeBuilt for multi-tenantPricing transparencyFits
Jamf ProApple onlyNo, partner programPublished list, volume quotesLarge Apple fleets, education, deep control
Iru (was Kandji)Apple plus Windows, AndroidNo, MSP program from 2026Quote basedTeams wanting automation and modular security
MosyleApple onlySeparate account per clientPublished, low cost tiersPrice sensitive Apple fleets
AddigyApple onlyYes, nativeQuote basedProviders running many Apple tenants
Microsoft IntuneCross platformPartial, via CSP tenantsBundled in M365 licensingMicrosoft-committed clients
JumpCloudCross platformYes, multi-tenant portalPublished per userIdentity plus device in one place
Hexnode UEMCross platformNoPublished tiersMixed fleets, kiosk and shared devices
SimpleMDMApple onlyMulti-accountPublished per deviceSmall fleets, straightforward needs
  1. Jamf Pro is the deepest Apple management product available, and the install base shows it. It scores 4.7 on G2 across 2,088 reviews and 4.7 on Capterra across 496, with a 2.0 on Trustpilot from 13 reviews. Reviewers consistently name two things: it handles anything Apple can do, and it costs more and takes longer to learn than the alternatives. For providers it's a single-tenant product wrapped in a partner program, so client separation is an operational discipline rather than an architectural guarantee.

  2. Iru is the vendor most buying guides still call Kandji. The company rebranded in October 2025 and the change went well past the name. Iru added Windows and Android management, split EDR, vulnerability management, identity and compliance into separately licensed modules, and launched an MSP channel program in May 2026 pitched on Apple plus Windows in one console. Ratings still sit under the old brand: 4.7 on G2 from 716 reviews, 4.9 on Capterra from 58, and 2.5 on Trustpilot from 5. The automation library is genuinely strong. The modular licensing means the quote you get in month one isn't the quote you get once security modules are switched on.

  3. Mosyle competes hard on price and gets credit for it, with value-for-money scoring 4.8 in its Capterra breakdown. It holds 4.6 on G2 from 53 reviews, 4.6 on Capterra, and 2.8 on Trustpilot from 3. The recurring complaint across all three is support responsiveness, with reviewers describing ticket-only escalation and no route to a named contact. Mosyle's per-client account model does have one advantage for providers: when a client wants direct ownership of their own environment, that conversation is simpler.

  4. Addigy is the one built for this job. Multi-tenant is the architecture, not a portal bolted on, so separate client fleets carry isolated policies, reporting and billing inside one console. It scores 4.5 on G2 from 225 reviews, 4.7 on Capterra from 13, and 3.2 on Trustpilot from a single review, which is too thin to read anything into. One Capterra reviewer captures the appeal precisely, describing the value as managing a large number of computers with few people and setting up procedures for multiple clients in one interface. The ceiling is real though: Addigy is Apple only, so the moment a client's Windows estate needs the same treatment you're running two consoles again.

  5. Microsoft Intune is the default when the client is already paying for it, since Apple management is included in the M365 licensing many clients hold. It scores around 4.5 on G2 across 265 reviews and 4.5 on Capterra, with no product-level Trustpilot listing. Its Apple support has closed a lot of ground, but it still trails the Apple-native tools on macOS depth, and multi-tenant work runs through CSP tenant switching rather than a single console. We went deeper on the trade-offs in our Microsoft Intune review.

  6. JumpCloud merges directory, identity and device management, which is a genuine advantage when the alternative is buying three products. It holds 4.5 on G2 from 3,931 reviews, 4.7 on Capterra from 190, and 3.4 on Trustpilot. It offers a multi-tenant portal for providers. Mac management depth sits below Jamf and Addigy, so it fits best where identity is the bigger problem and Apple config is straightforward.

  7. Hexnode UEM covers mixed fleets and is unusually good at kiosk and shared-device scenarios. It scores 4.5 on G2 from 247 reviews, 4.6 on Capterra from 153, and 3.5 on Trustpilot from 65, the largest Trustpilot sample in this group. Support quality splits sharply between the two review populations. There's no multi-tenant console, so it suits providers with a handful of Apple clients rather than a book of them.

  8. SimpleMDM does exactly what the name says, and reviewers like it for that. It holds 4.7 on G2 from 12 reviews and 4.8 on Capterra from 40, with no Trustpilot listing found as of August 2026. Multi-account support handles a small client book. It won't carry complex compliance work, and it isn't trying to.

Scalefusion and ManageEngine Mobile Device Manager Plus also rank for these searches. Both are competent, and both treat Apple as one platform among several rather than the main event.

Why the Review Scores Contradict Each Other

Look at the pattern across all eight: G2 and Capterra scores cluster between 4.5 and 4.9, while Trustpilot scores for the same vendors sit between 2.0 and 3.5. That gap is not noise, and it's worth understanding before you weight any of it.

G2 and Capterra are vendor-integrated. Vendors run review campaigns, incentivize submissions and route satisfied customers to those pages, which is legitimate and also selects for a happier sample. Trustpilot pages for these vendors are mostly unclaimed and uncampaigned, so the people arriving are the ones motivated enough to search out a place to complain. Jamf's 13 Trustpilot reviews and Addigy's single review are not representative samples of anything.

The useful signal isn't the number, it's the repeated theme. Mosyle's support complaints appear on Capterra and Trustpilot both. Jamf's cost and learning curve show up in its G2 and Capterra reviews despite the 4.7. Read the one and two star reviews for recurring operational failures, ignore the aggregate, and treat any product with fewer than about 50 reviews on a platform as unscored.

How to Pick

Run the client's constraint first, then the vendor list. If the fleet is Apple only and you're managing more than roughly ten client tenants, Addigy's architecture saves more technician time than any feature comparison will show you. If clients are mixed Apple and Windows and already on M365, Intune plus a native tool for macOS depth usually beats forcing one product to do both, and our unified endpoint management guide covers where that line falls.

If the client insists on owning their own environment, Mosyle's account separation and Iru's newer MSP program both make that handover cleaner than a single shared tenant would. If Apple config is simple and identity is the real problem, JumpCloud collapses three purchases into one.

Whichever way it lands, ask every vendor the same three questions before signing. Do you support declarative software update enforcement today, given the 2026 removal of the legacy commands. Whose Apple Business Manager account and APNs certificate hold the client fleet, and what does offboarding take. What does the price look like at triple the device count, since per-device pricing and module licensing both move on you as clients grow.

Where This Sits in a Consolidated Stack

Apple MDM is one more console in a stack that's already too wide. That's the trade providers keep making: the tool with the deepest platform support is rarely the tool that fits the rest of the operation, so the console count climbs and the margin doesn't.

Flamingo is building OpenFrame as an AI-native all-in-one MSP and IT platform, with native PSA included rather than sold separately, and pricing that doesn't punish you for growing. The point isn't that one platform absorbs every specialist tool, because Apple management at depth is genuinely specialist work. It's that everything around it, ticketing, automation, documentation and billing, doesn't need to be eight more vendors with eight more contracts and eight more renewal negotiations.

Pick the Apple MDM your client's fleet and your tenant count call for. Then count how many consoles are left.

Apple already killed the wipe. The only thing keeping you on the wrong MDM now is the paperwork.

Kristina Shkriabina

Marketing Manager

Ohayo! I'm Kristina, and I'm doing good things with content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Apple MDM

Apple MDM is a management protocol built into macOS, iOS and iPadOS that lets an approved server send commands to enrolled devices. It pushes configuration profiles, installs apps, enforces encryption and passcodes, reports compliance, and can remotely lock or wipe a lost device.
No. Apple Business Manager handles enrollment, organization identity, Managed Apple Accounts and app licensing through Apps and Books. It cannot push a configuration profile, deploy software or wipe a device. You connect it to a separate MDM, which does the actual device management work.
Apple Business Manager itself is free. MDM vendors charge separately, typically per device or per user per month, with Mosyle and SimpleMDM publishing low entry tiers and Jamf, Iru and Addigy quoting by volume. Intune is often already bundled in Microsoft 365 licensing.
Apple provides the MDM protocol and Apple Business Manager free, but not a full MDM server. Some vendors offer free tiers capped at low device counts. For a business fleet you need a paid third-party MDM connected to your Apple Business Manager account.
For providers managing many client fleets, multi-tenancy matters more than feature depth. Addigy is built around it natively, and JumpCloud offers a multi-tenant portal. Jamf, Iru and Mosyle handle multiple clients through partner programs or separate accounts, which costs more technician time at scale.
Yes, on current hardware. With macOS 26, iOS 26 and iPadOS 26, Apple Business Manager and Apple School Manager support migrating a device to a different device management service without a factory reset. That removes the main switching cost that kept fleets on outgrown tools.

About OpenFrame

Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
In the cloud, on US soil. Your data stays stateside.

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.