3 ms·
There is a lot of innovation, with many viable options, in the Apple MDM market. Kandji, FleetDM, micromdm, etc. In my experience, Jamf is only the ‘gold standa
by w0de0 3y ago
There is a lot of innovation, with many viable options, in the Apple MDM market. Kandji, FleetDM, micromdm, etc. In my experience, Jamf is only the ‘gold standard’ when one has only cursory knowledge of the space.
- wkat4242 3y agoI understand, I'm mainly talking from my enterprise background. From what I know the newer developments focus a lot on Apple specific implementations like DEP enrollment. Unfortunately we can't use that because we can't use Apple federated accounts (they still require the UPN and email to be the same which we can't comply with) and because our IDP isn't supported. This is the problem in enterprise, where you're often stuck with a relatively small amount of Macs (in our case less than half a percent) and thus the macs have to comply with the rest of the environment. Because the environment isn't going to be adapted to Apple's requirements. We're stuck with the requirement to limit user admin rights, to have security proxies (Zscaler), and many other things that don't work seamlessly on a Mac. Like the built-in password restrictions MDM profile, this is way too basic to fully encompass our security policy (it seems more like a mobile one shoehorned onto a Mac). So we need a lot of workarounds to meet our security policy. For this JAMF works really well because it has lots of workarounds for enterprise setups that aren't done "the Apple way". If you're free from legacy constraints the more modern solutions work great but in our environment we don't have that luxury, sadly. There's just too many strings attached from the security side. You can sometimes script your way around the issues but every major macOS update will break things and JAMF is pretty good at figuring all this stuff out. But yes I should have mentioned that context.