Intune Isn't Free: What Bundled Device Management Really Costs

• 2Fifteen Tech
Iru Device Management Apple Microsoft Cybersecurity
Iru logo

Intune is rarely chosen. It arrives. It comes bundled with Microsoft 365 Business Premium, E3, or E5, it shows up as a line item that costs nothing extra, and it becomes the device management tool by default before anyone has compared it to anything else.

Iru recently published a piece on exactly this, Intune pricing: What your bundled MDM is actually costing you, and it lines up with what we see when we look at new customers’ environments. The license may be included. Running it is not.

This post walks through where that cost actually lands, how to put it in terms your finance team will accept, and what a move to Iru looks like when the numbers make sense.

Two Costs, Only One on the Invoice

Every device management platform has two prices: what you pay for the license, and what it takes to operate. Intune scores well on the first and quietly runs up the second. Iru’s article breaks the operating cost into a few buckets, and they match our experience.

Third-party app patching becomes someone’s job

Intune handles Microsoft’s own apps and OS updates reasonably well. Everything else is on you. Chrome, Zoom, Slack, Adobe, your line-of-business tools: each one has to be packaged, tested, uploaded, and deployed, then done again every time a new version ships.

Microsoft does offer a prepackaged catalog called Enterprise App Management, but it covers Windows apps, and it’s only included with E5 or as a paid add-on. If you’re on Business Premium or E3, or if your fleet is mostly Macs, that shortcut doesn’t help. For Apple devices in Intune, keeping third-party apps current is largely a manual, recurring task.

That isn’t a one-time setup cost. It’s a standing chore, paid in hours every release cycle.

Waiting, and not knowing

According to Iru, Intune’s routine maintenance check-in runs roughly every eight hours. Some changes push faster, but the bigger issue is visibility. There’s no clean per-device view of what has landed, what’s still pending, and what quietly failed. Someone ends up chasing deployment status by hand, and devices can drift out of compliance well before anyone notices.

Two consoles for one job

Intune manages the device. Endpoint detection and vulnerability management live in Microsoft Defender, a separate product with its own console. Spotting a problem in one tool and fixing it in another adds friction to every security issue, and that friction never shows up on an invoice either.

Answering “Why Pay for Something We Already Have?”

This is the question that stalls most device management conversations, and it’s a reasonable one if the cost of Intune really were zero. It isn’t. It’s paid in a different currency:

  • Admin hours spent packaging and patching third-party apps, every release, on every platform.
  • Add-on licenses bought to close gaps the bundled tier leaves open.
  • Time lost chasing deployment status across devices that check in a few times a day.
  • Risk carried by every device nobody can confidently confirm is patched and compliant.

Put real numbers next to those items, hours per week, add-on spend, and how many devices are out of date at any given moment, and the conversation changes. It stops being “why replace something free” and becomes “why are we paying for device management in labor instead of in a tool built to do it.”

What Iru Does Differently

Iru automates much of that work, and keeps management and security in the same place:

  • Device check-ins every 15 minutes, so changes land quickly instead of sometime later today.
  • A clear patch timeline per device, showing whether a machine got an update, missed its deadline, or failed with an error.
  • Auto Apps, a maintained catalog of more than 450 applications that Iru packages, deploys, and patches automatically, included with Iru Endpoint.
  • Endpoint detection and vulnerability management in the same console as device management, so finding a problem and fixing it happen in one place.

For Apple-heavy organizations there’s another factor. Iru (formerly Kandji) was built for Apple first. Zero-touch deployment through Apple Business Manager, OS update enforcement through Declarative Device Management, and Mac-specific controls like macOS LAPS are core to the platform, not translations of a Windows management model. We’ve written more about that in Why Iru Isn’t Just Another MDM.

What the Move Actually Looks Like

As an Apple Technical Partner and Iru partner, we run Iru for every Apple environment we support. Here’s what a move off Intune looks like with us.

Real figures to bring to finance. We look at your current fleet and how it’s actually being managed: how patching gets done today, how long it takes, what add-ons you’re paying for, and how many devices are behind. That turns a general argument that a different tool is better into numbers your finance team can check.

Nothing you rely on gets lost. We map what Intune is doing for you today (configuration profiles, compliance policies, apps, enrollment) to its equivalent in Iru, and decide what to carry over, what to rebuild, and what to drop. Most environments have accumulated policies nobody remembers creating. A migration is a good time to clear those out.

Moving devices so people keep working. We stage the move so people keep working. For Macs, that includes reassigning devices in Apple Business Manager so future enrollments land in Iru automatically, and walking each user through the switch so nobody is left guessing.

Day-to-day management afterward. Once you’re on Iru, we manage it day to day: patching, OS updates, new device enrollment, security alerts, and keeping policies current as your team changes. Support is during business hours, with automated monitoring watching your fleet the rest of the time. When the migration is done, we give you a walkthrough and written handoff so you know exactly what’s in place and how to reach us.

You don’t have to leave Microsoft 365 to do any of this. Plenty of teams keep Microsoft for email, files, and identity, and use Iru for the devices themselves.

Is It Worth Switching?

Not always. If your fleet is small, mostly Windows, and Intune is genuinely low-effort for your team, the bundled license may be the right answer. The point isn’t that Intune is bad. It’s that “free” is the wrong way to measure it.

If your team is spending real time on manual patching, your Macs feel like second-class citizens in a Windows-first tool, or nobody can say with confidence which devices are up to date, that’s a cost you’re already paying, and it’s worth knowing the number.

Want to Put a Number on It?

Tell us a bit about your fleet and how it’s managed today, and we’ll help you figure out what Intune is really costing you and whether Iru is a better fit.

Tell Us What You Need

Tell us about your team and what you'd like help with. We'll follow up during business hours to understand the fit and arrange a conversation.

All fields except phone are required.

Prefer to talk? Call 385-722-5140. Already a customer? Visit the service desk.

Related Services