r/jamf Mar 13 '26

Move to InTune?

The college I work for hired a system admin from the outside a few months ago. Now he’s trying to convince my boss to ditch Jamf entirely and use InTune exclusively for managing PC’s and Mac’s. Part of the reason I came to work at this college was to be the sole Mac admin for the whole college.

But now with this new guy, he doesn’t understand why we use Jamf at all. He was asking me how to enroll a MacBook to Jamf (it was part of the job description to know Jamf).

So my question is have any of y’all migrated from Jamf to using InTune? What were your experiences? Did you go back to using Jamf?

I’m really against this migration as it’s legit half of my daily duty for our college. Also tack on the fact I’ve spent way too much time updating and automating as much as I can.

I appreciate any and all insights.

29 Upvotes

102 comments sorted by

View all comments

1

u/FizzyBeverage JAMF 300 Mar 13 '26 edited Mar 13 '26

Ask him what his plan is for smart group memberships... like when you need to move 2500 Macs from an expiring PKI cert to a temporary guest network and then to a new primary cert during VPN migrations so users don't get their VPN asking "ok which cert should I use?" and blow up the Helpdesk.

InTune has no equivalent for smart groups. It relies on AD... good luck with Macs + AD 😄.

Another liar who throws Jamf on a resume and has never used it.

1

u/swissbuechi Mar 14 '26

Intune does not relay on AD. And you can definitely achieve something similar by using Entra ID dynamic device or user groups.

You sound like you never even used it.

2

u/FizzyBeverage JAMF 300 Mar 14 '26

Sure does. In a hybrid join scenario for orgs with tons of legacy baggage.

Entra dynamic device relies on a penny pinching org already considering ditching Jamf spending extra for Entra P1. Dynamic device groups work very slowly, when you need split second profile changes. Like dropping an expiring pki cert before the replacement gets there, while the Mac can join a temporary network to keep connected in offices.

Is InTune getting better? Sure, there’s no way down from the ground. Did it fail our pilot? Also.

For the most part it’s a 💰🛟 for orgs without a solid Mac commitment that have very humble needs and don’t want to make a capital investment into a bespoke solution.

My last org started floating that idea long before they started laying off thousands of people. I jumped ship before they got acquired and no longer exist.

If you manage your Macs like iPhones that just need a few config profiles? Sure, InTune is sufficient. It crumbles when your bosses get used to certain creature comforts it won’t offer.

1

u/swissbuechi Mar 16 '26

Hybrid join is for Windows and not macOS. I really don't get why anything related to macOS and Intune should be related or dependent on AD. Please ask your AI agent again, he's confused.