Financial documents and calculator on a desk illustrating per-device MDM licensing costs for large Apple fleets

MicroMDM vs Jamf Pro

October 11, 2026 · 12 min read · By Nadia Kowalski

Key Takeaways:

  • Jamf’s published business pricing lists $12.50 per macOS device per month and $5.75 per mobile device per month, billed annually with a 25-device minimum, per Jamf’s pricing page.
  • Open source MicroMDM has no per-device license fee, but the savings come with engineering time for certificates, SCEP, TLS, and server operations.
  • MicroMDM v1 entered maintenance mode in June 2025; the project’s own guidance directs long-term deployments to NanoMDM as the successor.
  • Both platforms use the same Apple MDM protocol, so enrollment and certificate handling are the same; the difference lies in what you build around the server.
  • For ISO 27001 and SOC 2, the compliance gap is not the tool but the evidence: auditors check whether controls operated, not which vendor you chose.

Jamf’s published business pricing lists $12.50 per macOS device per month and $5.75 per mobile device per month, both billed annually with a 25-device minimum, according to the vendor’s pricing page. At fleet scale the per-device fee becomes the largest line item in the endpoint budget. Open source MicroMDM charges no fee per device, which drives much of the discussion about cost-effective Mobile Device Management in Apple-heavy enterprises, and is also the fact most likely to mislead a CISO who stops reading there.

This analysis compares the two approaches on licensing structure, deployment effort, feature coverage, and audit evidence. It builds on the site’s earlier series on deploying MicroMDM and NanoMDM for small fleets and the comparison of third-party MDM platforms, extending both into the enterprise-fleet and compliance context.

The Cost Gap in Numbers

Jamf’s business plans are quoted per device per month with an annual commitment and a 25-device minimum. At the macOS rate the vendor publishes, a fleet in the low thousands reaches six figures annually in licensing alone, before paying any administrators. Adding mobile devices adds a second per-device charge. The exact total depends on fleet mix, but the structure matters: cost increases linearly with every device added.

Deployment Effort and the Hidden Cost of Free

MicroMDM’s license cost is zero. The project describes itself as “free, open source, and permissively licensed,” and the repository is MIT-licensed, so there is no device count, no minimum, and no renewal negotiation. What replaces the license fee is infrastructure and labor: a host with uptime, backups, and patching; a SCEP service for device identity certificates; TLS termination; and the Apple Push Notification service certificate renewed annually. Those are fixed costs, not per-device costs, which is the structural difference that matters at scale.

The break-even point is where fixed operational cost equals the avoided license fee. A self-hosted stack that requires significant engineering time and infrastructure each year crosses over against Jamf’s Mac pricing somewhere in the low hundreds of devices. Below that, a commercial subscription is usually cheaper once labor is accounted for. Above it, the gap grows with every device added. The build-versus-buy analysis from Fora Soft frames the same crossover for a fully custom MDM build, a higher figure that reflects building from scratch rather than assembling MicroMDM and its companion components.

What Each Platform Actually Does

MicroMDM is an open-source Mobile Device Management server for Apple devices, written in Go and licensed under MIT. The project’s stated goal is “a performant and extensible device management solution for enterprise and education.” It uses the Apple MDM protocol directly, integrating with Apple Business Manager and Apple School Manager enrollment workflows. It exposes APIs for scheduling commands, reading device data, and managing the server itself, and supports device enrollment, remote wipe, and profile management.

Jamf Pro is a commercial Apple-only management platform. The vendor describes Jamf for Mac as covering “core macOS device management and workflow automation,” endpoint protection, vulnerability management, content filtering, and identity and access management, powered by Jamf Pro, Jamf Connect, and Jamf Protect together. Jamf for Mobile adds mobile threat defense and zero-trust network access. Jamf manages Apple operating systems rather than Windows or Android, which is why it can go deep on Apple-specific workflows.

Jamf bundles several products that a MicroMDM deployment must assemble from separate components. MicroMDM is the MDM protocol server; it does not include a SCEP service, TLS termination, an enrollment profile generator, or identity integration. Each of those is something the operator provides. Jamf delivers them under one subscription and one support contract. The trade-off is control and cost against integration and support.

Framework Comparison Across MDM Requirements

The table below compares the two approaches across the requirements that appear in an enterprise MDM procurement. Every row is drawn from the projects’ own documentation and the vendor’s pricing page; where a capability is not documented, the row is omitted rather than guessed.

Requirement Open Source MicroMDM Jamf Pro (business plans)
License model MIT, no per-device fee $12.50 per macOS device/month; $5.75 per mobile device/month, 25-device minimum
Apple MDM protocol support Yes, integrates with Apple Business Manager Yes, Apple-only platform
Device enrollment, wipe, profiles Yes Yes
SCEP, TLS, enrollment profiles Not included; operator provides Bundled in the platform
Identity and access management Not included; integrate separately Jamf Connect included in Jamf for Mac
Endpoint protection / threat defense Not included Jamf Protect included in Jamf for Mac and Jamf for Mobile
Vendor support contract Community (MacAdmins Slack), no commercial support Standard chat, email, and phone support

Sources: MicroMDM project site and Jamf pricing.

MicroMDM covers the protocol layer and leaves the surrounding product layer to the operator. Jamf covers both and prices accordingly. For an organization that needs identity integration and endpoint protection on day one, the Jamf bundle removes three separate procurement and integration projects. For one that already has an identity provider and its own endpoint tooling, much of the Jamf bundle duplicates what it has already paid for, which is where the cost argument for open source becomes credible.

Deployment Effort and the Hidden Cost of Free

Open-source MDM is not free in the way finance teams usually consider it. The licensing line item is zero, but the operational costs are not. A TechTarget analysis of open-source MDM states the trade-offs clearly: the code “can require pricey expertise to customize, deploy, maintain or scale,” integration with other tools can be difficult, migration takes significant time and resources, and documentation “might be inconsistent, incorrect or out of date.” These are costs that belong in the business case.

The specific operational tasks in a MicroMDM deployment are clear. The Apple Push Notification service certificate has a fixed annual lifespan and must be renewed with the same Apple ID that created it, and the APNs topic embedded in the certificate cannot change during a device’s enrollment, which means swapping certificates requires re-enrolling every device. A SCEP service must be set up for device identity certificates. TLS must be terminated and kept current. Backups, monitoring, and patching are the operator’s responsibility. None of this is unusual for a team that already runs Linux services, but it is the difference between a subscription and a project.

The initial work is front-loaded. After the server is running, certificates are automated, and the enrollment profile is stable, ongoing maintenance involves backups, monitoring, and the annual certificate renewal. The main risk is not the initial build but neglect. An expired push certificate stops management commands from reaching devices without immediate notice, and the fleet continues running unmanaged until someone detects the issue. Treating certificate lifecycle as a primary operational concern from day one separates a functioning self-hosted deployment from repeated incidents.

Compliance Mapping: GDPR, SOC 2, and ISO 27001

Auditors do not certify tools; they check whether controls operated. GDPR Article 32 requires “appropriate technical and organizational measures” proportionate to risk, and it names encryption, resilience, and regular evaluation of security measures. A device management platform contributes to that evidence by enforcing FileVault, passcodes, and OS update baselines. Both MicroMDM and Jamf can enforce those settings because both use the same Apple management protocol. The platform is not the control; the configuration applied through it is.

Where the two differ is in the evidence trail. ISO 27001:2022 Annex A includes control A 8.1 on user endpoint devices and A 8.24 on cryptography, both of which require documented, operating controls. A commercial platform comes with built-in reporting, audit logs, and role-based administrator access that map clearly to those requirements. A self-hosted MicroMDM deployment must produce that evidence from its own logs and APIs, and must document the certificate, access, and backup procedures that keep the control operating. That is the kind of work the site’s security audit preparation checklist describes as the difference between a control that exists and a control that passes an audit.

For SOC 2, a Type II report tests whether controls operated over a sustained period. An organization running self-hosted MDM must show that its access reviews, change management, and monitoring ran continuously, not just that the server was configured correctly once. The common audit findings here are missing evidence of control operation, incomplete access reviews, and undocumented changes, and those findings relate to process, not the vendor. A commercial subscription reduces the effort required to generate that evidence; it does not remove the obligation to maintain it.

The MicroMDM Lifecycle Question

Any long-term business case for MicroMDM has to consider project status, because that is where the cost argument can quietly reverse. In June 2025, the project maintainer published a post confirming that MicroMDM v1 had entered maintenance mode: no new feature work, with security and bug fixes on an available-effort basis, and official guidance to migrate to NanoMDM and the Nano-suite of projects. The repository remains active and functional, but it is not the project to plan a five-year deployment around.

NanoMDM is the successor, described by its own documentation as “a minimalist Apple MDM server and library heavily inspired by MicroMDM.” It is MIT-licensed, written in Go, actively maintained, and supports MySQL and PostgreSQL storage backends with horizontal scaling. It deliberately excludes SCEP, TLS termination, enrollment profile generation, and VPP integration, so the operator provides those. A migration from MicroMDM to NanoMDM is not in-place; the APNs topic constraint means it requires phased re-enrollment, typically piloted with a small group before rolling out in waves.

An organization evaluating open source for a fleet it intends to keep for a decade is really evaluating NanoMDM, not MicroMDM, and should budget the migration as part of the plan. The cost advantage remains after that migration because the license model is unchanged, but the project risk is real and should be included in the risk register alongside the cost savings.

Implementation Checklist and Audit Timeline

A disciplined rollout produces auditable evidence at every step, which turns a technical deployment into a defensible control. Each item below yields documentation an auditor can review.

  • Confirm the enrollment foundation (weeks 1-2). Verify that Apple Business Manager is configured and that new devices are purchased through channels that assign serial numbers to your organization. Without this, no MDM can deliver zero-touch enrollment, and manual exceptions become the main operational cost.
  • Decide build versus buy against a device count (week 2). Model the annual license fee at your current and projected fleet size, then compare it against loaded engineering time plus infrastructure. The crossover sits in the low hundreds of devices for a self-hosted stack; below it, the commercial subscription usually costs less.
  • Stand up the supporting services (weeks 3-6, self-hosted path). Provision the server, SCEP service, and TLS termination, and obtain the APNs push certificate. Document the renewal owner and calendar reminder before the first device enrolls.
  • Define the security baseline (weeks 4-6). Enforce FileVault, passcodes, screen lock, and OS update expectations, and map each setting to the framework control it satisfies (GDPR Article 32, ISO 27001 A 8.1 and A 8.24).
  • Automate evidence collection (weeks 6-10). Export encryption status, OS version, and access logs on a schedule, and route them to your SIEM or GRC platform. This step determines whether audit preparation takes a week or a quarter.
  • Run a loss and offboarding tabletop (week 10). Confirm who approves lock, wipe, and data preservation, and that the logging captures the action. A control that cannot be shown in operation is treated as a control that does not exist.

For a mid-sized enterprise, a realistic timeline is three to six months for the commercial path and four to eight months for the self-hosted path, with the extra time going to certificate work, evidence automation, and the pilot. Organizations that shorten the timeline typically skip the evidence-automation step, which causes the most expensive findings later.

Common Pitfalls and What They Cost

Pricing the license and forgetting the labor. A business case that shows a six-figure annual license replaced by a no-fee license is incomplete. The self-hosted path adds engineering time, infrastructure, and ongoing certificate and monitoring work. If that loaded cost exceeds the license fee at your device count, the open-source path costs more, not less.

Assuming the platform is the compliance control. Encrypting devices through any MDM does not by itself satisfy GDPR Article 32 or ISO 27001. The control is the enforced configuration plus the evidence that it operated. Organizations that buy a tool and skip the evidence automation find the gap during the first audit.

Ignoring the certificate lifecycle. The annual APNs certificate renewal is the most common silent failure in self-hosted management. An expired certificate stops management commands without an obvious alarm, and the fleet drifts out of policy until someone notices.

Planning on a project that is in maintenance mode. Building a five-year plan around MicroMDM v1 ignores the project’s own guidance. The successor is NanoMDM, and the migration requires phased re-enrollment, not an upgrade. Budget it from the start.

Jamf Pro fits organizations that need bundled identity, endpoint protection, and vendor support on day one, and the published per-device pricing reflects those costs. Open source MicroMDM, and its successor NanoMDM, fit organizations with in-house Apple engineering, an existing identity and security stack, and a fleet large enough that a per-device fee becomes the largest line item. The cost savings are real above that threshold. So is the work required to achieve them.

More in-depth coverage from this blog on closely related topics:

Sources and References

Sources cited while researching and writing this article:

Nadia Kowalski

Has read every privacy policy you've ever skipped. Fluent in GDPR, CCPA, SOC 2, and several other acronyms that make people's eyes glaze over. Processes regulatory updates faster than most organizations can schedule a meeting about them. Her idea of light reading is a 200-page compliance framework, and she remembers all of it.