Explore trending tools

Iru Review (2026): Pricing, Pros & Cons, Verdict | Siit

Discover how Iru handles zero-touch Apple deployment, automated patching, and built-in endpoint security for lean IT teams.

Tools > Explore trending tools >
Iru

Dimitri Cabete Jorge, Co-Founder & CTO · Last updated: August 2026 · Facts verified: August 2026

TL;DR verdict: Iru rebranded in October 2025 and stretched an Apple-only endpoint product across Windows and Android. Its edge is EDR and vulnerability management running inside the same agent and the same licence that Jamf splits across separate products. Its problem is that you cannot get a number without talking to sales, and practitioners report that year two erases the year-one discount. Apple-heavy teams who want managed security without Jamf's scripting depth fit well here. Budget-first buyers should look at Mosyle, and mixed-OS fleets at JumpCloud.

Ratings: G2: 4.7/5 (839 reviews) · Gartner Peer Insights: 4.3/5 (29 ratings), verified August 2026

What Is Iru?

Iru, formerly Kandji, is an Apple-rooted endpoint management and security platform, renamed in October 2025. Its support documentation describes the product as a security and IT system for protecting people, apps, and devices, with identity, device management, and compliance in one place.

Founded in San Diego in 2018 by a team that had been running Apple-focused managed services, the company spent its first years as a pure Apple MDM before the rebrand added Windows and Android. Its largest raise was a July 2024 Series D of $100 million from General Catalyst, split evenly between equity and go-to-market investment, at an $850 million valuation. Iru now reports 6,000+ companies on the platform.

Its public certification record lists SOC 2 Type II attestation plus ISO 27001:2022 and ISO/IEC 42001:2023 certificates, the second being the AI management systems standard, as published on Iru's trust center in August 2026.

What Is Iru Used For?

Iru's core job is giving IT automated control over a device fleet from the moment hardware ships to a new hire through ongoing patching, compliance evidence, and security response.

  • Zero-touch Mac deployment: IT drop-ships a laptop straight to a new hire, and apps and settings land on first startup with no hands-on setup time.
  • Automated OS and app patching: Iru packages, hosts, and updates a managed catalog of Mac and Windows applications, then prompts users and enforces installs when a deadline passes.
  • Continuous compliance evidence: Controls stay mapped to live evidence, so audit prep stops being a quarterly scramble through screenshots.
  • Vulnerability detection and response: Software inventory refreshes hourly, and patching fires against the managed catalog based on CVE severity.
  • Migration off a legacy MDM: The Migration Agent moves a fleet off Jamf or another MDM with only the approval taps Apple insists on.

Key Features of Iru

Seven capabilities carry the buying decision. The rest of the product is competent and unremarkable, and none of it is why teams switch.

  • Assignment Maps: Iru's current configuration model assigns apps and settings through a visual map with conditional logic, one map per device, so overlapping group membership stops producing contradictory settings. Classic Blueprints are still supported and still dynamically assignable, so a migration doesn't force a rebuild on day one. This is the feature that makes the product learnable in an afternoon, and the same design is why there is no Jamf-style criteria-based targeting underneath it.
  • Auto Apps: The managed app catalog covers 200+ Mac and Windows applications with automated packaging, hosting, and patching. Iru schedules quiet updates, prompts users, and enforces installs when needed, and Vulnerability Response accelerates patching against the same catalog by CVE severity. Migrating admins name this one first more often than anything else in the product.
  • Single-agent EDR and Vulnerability Management: Threat detection and containment runs machine-learning models inside the same agent as device management, with no second install. The vulnerability layer adds hourly software inventory, impact analysis, and autonomous patching, currently for Mac with Windows listed as coming soon. Jamf sells the equivalent coverage as separate products, which is the clearest cost argument in Iru's favor.
  • Iru AI: Launched with the October 2025 rebrand, Iru's agent layer puts purpose-scoped agents across the compliance, endpoint, and identity products. Each agent works from an Iru Context Model that maps devices, apps, users, policies, posture, and events. The governance shape is specific for an agentic layer this young: tenant-isolated context, least-privilege access, approvals, and full audit logs of agent activity. It is also nine months old, and almost all the evidence for it is vendor-published.
  • Prism: Prism is the device intelligence and query engine, and it's where teams with serious reporting requirements hit a ceiling. There are no custom attributes, which rules out any fleet query built on data you defined yourself. The workaround is a second tool, not a setting.
  • Workforce Identity: Passwordless SSO ties hardware-backed passkeys to a trusted device, which pushes Iru past device management into the territory covered by choosing an IAM platform. Whether you want your MDM vendor holding the identity layer is a fair question, and this product is years newer than the endpoint side.
  • Conditional Access: A documented Microsoft integration feeds device inventory and compliance state into Conditional Access policies, so only managed, compliant machines reach corporate resources. It covers macOS, iOS, and iPadOS only, which matters if the rebrand is the reason you're looking.

A Model Context Protocol (MCP) server exposes the fleet to AI build environments including Claude Code and Cursor, which is a 2026-native capability rather than a repackaged API.

Supported platforms (full compatibility matrix):

Platform Supported versions
macOS 14 Sonoma, 15 Sequoia, 26 Tahoe
iOS / iPadOS 16 and higher
tvOS 16 and higher
visionOS 2 and higher (Apple Vision Pro)
Windows, Android Listed on Iru's device management page

Version 16 sits at both the floor and the end-of-support line for iOS, iPadOS, and tvOS, with an end-of-support date of October 15, 2025.

Iru Pros & Cons

Iru trades Jamf's scripting depth for a console new admins learn quickly and security you don't licence separately, and that trade is worth understanding before you sign.

Pros Cons
Clean admin console that new admins learn quickly No published pricing; every product requires a quote
Visual configuration with conditional logic, no scripting required Renewal quotes frequently approach the Jamf pricing they undercut in year one
Auto Apps catalog (200+ apps) patches Mac and Windows automatically No equivalent to Jamf's Smart Groups for criteria-based device targeting
EDR and Vulnerability Management included without a separate licence Prism reporting has no custom attributes, which narrows advanced fleet queries
One agent covers device management, EDR, and vulnerability response Script deployment to specific users without Self-Service exposure is awkward
Migration Agent cuts a Jamf-to-Iru move to the taps Apple mandates Windows and Android management is new; vulnerability management is still Mac-only
24/5 live chat with vendor-stated response under two minutes Sold in 50-device increments, so small fleets buy capacity they don't use

What Users Say

Source Overall Notable subscores
G2 4.7/5 (839 reviews) Top pros: Ease of Use (339 mentions), Customer Support (251), Device Management (173). Top cons: Missing Features (71), Lacking Features (55), Limited Compatibility (51), Expensive (46)
Capterra 4.9/5 (490 reviews) Customer Service 4.9; Features 4.6; Value for Money 4.6; 99% positive sentiment; recognized for best ease of use in 10 categories
Gartner Peer Insights 4.3/5 (29 ratings) 96% of ratings at four or five stars; no Customers' Choice designation
r/macsysadmin Practitioner forum Praise for Auto Apps and migration smoothness; recurring concern about renewal pricing

What users consistently praise:

  • Admin console usability: Ease of Use is the single most-mentioned pro on G2 at 339 mentions, and Capterra recognizes the product for best ease of use across ten categories. Reviewers describe getting productive without a dedicated Mac admin on staff, which is the whole pitch and it lands.
  • Automation depth: Assignment Maps, the Auto Apps catalog, and zero-touch onboarding draw steady praise. The specific thing admins value is the pre-configured starting point: common configurations arrive built rather than assembled.
  • Support responsiveness: Customer Support is G2's second most-mentioned pro at 251 mentions, and Capterra's Customer Service subscore sits at 4.9, its joint-highest. Support is the one dimension where the platforms agree without qualification, and practitioners consistently describe reaching a human through in-console chat quickly. Migration assistance gets called out separately and often.

What users consistently complain about:

  • Renewal pricing: The shape is familiar if you've sat through it. You benchmark Iru against your current Jamf invoice, sales comes in comfortably under it, you sign, and eighteen months later the renewal quote arrives within a few dollars of the number you left. Was the discount real? For twelve months, yes. G2 reviewers file the rest under Expensive 46 times, and the pattern is consistent enough that year-two pricing belongs in the year-one negotiation.
  • Missing Jamf parity features: The absence of Smart Groups, Jamf's criteria-based dynamic grouping, is the single most-cited gap among practitioners who have switched. Blueprint layering gets described as clunky for one-off or heavily customized configurations.
  • Reporting and scripting ceiling: Prism is repeatedly called limited, and the lack of custom attributes pushes teams toward supplemental tooling for fleet visibility. Deploying a script to specific users without exposing it in Self-Service isn't straightforward from the web console.

Where reviewers diverge:

  • Feature depth against usability: Features is Capterra's joint-lowest subscore at 4.6, three-tenths under an overall of 4.9, and G2's two most-mentioned complaints are Missing Features and Lacking Features. The same reviewers rating the console easiest-in-class rate the feature surface lowest, which is the honest signature of a product that removed configurability on purpose.
  • Value for money: Value for Money also sits at 4.6 on Capterra, which reflects buyers who negotiated a favorable first contract. Practitioner forums tell a more complicated story once renewal arrives, and the gap between initial and lifetime cost perception is worth modeling before you commit.
  • Platform breadth: Gartner's 4.3 sits four-tenths below G2's 4.7 on a much smaller sample, and Limited Compatibility appears 51 times in G2's cons. Buyers scoring the Apple fleet and buyers scoring a mixed estate are not rating the same product.

Iru Pricing

Iru does not publish list pricing; every product requires a custom quote on an annual commitment.

Product Price Notes
Endpoint Management Quote-based 14-day free trial available
Endpoint Detection & Response Quote-based 14-day free trial available
Vulnerability Management Quote-based 14-day free trial available
Workforce Identity Quote-based 14-day free trial available
Compliance Automation Quote-based Demo only, no self-serve trial
Trust Center Quote-based Demo only, no self-serve trial
Onboarding and migration Included Included with all plans
Support Included 24/5 chat, vendor-stated response under two minutes

Gotchas:

  • Procurement estimate, separate from Iru's pricing page: Vendr data puts per-device cost at roughly $30 to $80+ per year depending on product mix, with a median buyer paying $18,888 annually across 459 recorded purchases.
  • Buyers in that same Vendr dataset save 15% on average against the opening quote, so treat the first number as a starting position rather than a rate card.
  • Vendr also reports licences selling in buckets of 50 devices, which Iru does not publish. On that structure a 60-device fleet pays for 100.
  • Renewals frequently land well above first-year pricing. Locking a multi-year term at purchase is the remedy practitioners keep recommending.
  • The 14-day free trial covers Endpoint Management, EDR, Vulnerability Management, and Workforce Identity. Compliance Automation and Trust Center are demo only.
  • Contracts are annual commitments billed annually, with no monthly billing option published.
  • Onboarding and migration support carry no additional cost. That covers the Migration Agent and hands-on help from Iru's migration team.
  • Best per-device rates cluster in deployments of roughly 50 to 500 devices. Smaller fleets pay a higher per-device rate.

Is Iru Worth It?

Yes, if your fleet is predominantly Apple, you want managed security without buying and integrating a separate EDR product, and you'd rather have fast onboarding and reliable support than deep scripting flexibility. Teams migrating off Jamf get a well-supported path across, and the built-in compliance automation earns its keep for organizations chasing SOC 2 or ISO 27001 without a dedicated governance, risk, and compliance (GRC) platform.

Look elsewhere if you need a published price before you talk to sales. Iru won't give you one, and renewal pricing is an open concern in practitioner communities. For a lower-cost Apple MDM with transparent pricing and a free tier for small fleets, Mosyle is the right call. If your environment is mixed-OS or you need mature Windows and Android management today, JumpCloud covers Mac, Windows, Linux, iOS, and Android from one platform. Either way, the deeper question is how much of Jamf's depth you actually use, which is where the comparison gets specific.

Iru vs Jamf

Jamf is the established Apple MDM market leader and Iru is the challenger that trades depth and configurability for a cleaner console and integrated security. The practical difference comes down to one question: does someone on your team write and maintain Mac policy, or does your team configure it?

Iru bundles EDR and Vulnerability Management into its core platform, where Jamf licenses Jamf Protect and Jamf Compliance Reporter separately. Iru's automation model is built to remove the scripting and custom policy work Jamf power users depend on. That's an asset for a team without a dedicated Mac admin and a constraint for a team that needs Jamf's API surface or Smart Group flexibility.

Where Iru Wins:

  • Time to value: The no-code configuration model gets new admins productive faster, and reviewers describe the difference in weeks rather than months.
  • Integrated security: EDR and vulnerability management ship in one agent under one licence, where Jamf charges separately for equivalent coverage.
  • Offline enforcement: The Iru agent enforces configuration and compliance locally, so devices stay in policy while disconnected. Jamf's offline behavior is limited to basic MDM functions.
  • Mid-market pricing: Procurement data puts the most competitive per-device pricing in deployments of roughly 50 to 500 devices, particularly in the first contract year.
  • Automated migration: The Migration Agent holds user interaction during a Jamf-to-Iru move down to what Apple insists on approving.

Where Jamf Wins:

  • API depth: Jamf's API exposes thousands of commands. Iru's published API reference is a far smaller surface, which matters if your workflows script against the platform rather than configure it.
  • Reporting breadth: Jamf Pro's report builder exposes far more criteria than Prism, and Prism's lack of custom attributes means the gap widens exactly where fleet reporting gets specific.
  • Customization for power users: Smart Groups, complex scripting, and granular policy controls give Jamf administrators room for enterprise-scale niche workflows Iru's model doesn't reach.
  • Compliance depth: Jamf ships CIS, NIST, and STIG compliance templates, which matters in regulated environments where an auditor expects a named framework.
  • Education and government: Jamf holds a dedicated network for K-12, higher education, and government buyers.
  • Analyst placement: Jamf was named a Leader in IDC's December 2025 unified endpoint management assessment for Apple devices (#US53003225). Worth knowing for a smaller fleet: in the same cycle's SMB assessment (#US53003425), Jamf placed as a Major Player rather than a Leader.

See the full Iru vs Jamf comparison.

Iru Alternatives

Two alternatives map onto the two reasons teams walk away from Iru: price transparency and mixed-OS coverage. Both sit inside a broader shortlist of Apple and cross-platform options.

Mosyle: Pick this if cost is the deciding factor. Mosyle publishes its rates. Business FREE covers up to 30 devices at no charge, and Business PREMIUM runs $1.00 per device per month with a 30-licence minimum billed annually. Fuse for iOS, iPadOS and visionOS is $1.50, and Fuse for macOS is $3.00, which is the tier an Apple-first team should actually price against. Mosyle also offers a six-month extended trial to teams on another Apple management provider, plus a migration credit equal to the full first year, so year one costs nothing.

JumpCloud: Pick this if your fleet spans more than Apple, or if Windows and Android need managing at the same depth as Mac today rather than on Iru's roadmap. The Device Management plan runs $9 per user per month billed annually, $11 billed monthly, and the identity-first directory model covers device management and user lifecycle in one system.

Whichever MDM you land on, the device record still lives in a console your employees never open, and the person answering "my laptop is locked and I am on a train" still has to go find it.

How Iru Works With Siit

Iru is a native Siit integration. Siit syncs the Apple fleet from Iru into its Unified Data Model, pulling model, serial number, OS and version, asset tag, assigned user, enrollment state, blueprint assignment, and last check-in. From a request, an agent can lock the device, wipe it, or open the full record in the Iru console, and employees raise the request in Slack or Teams without opening anything new.

Two boundaries worth knowing. Those three actions run from the request side panel only, with workflow and IT Agent availability listed as coming, so nothing wipes a laptop automatically on an offboarding date. And Iru handles the device, not the account: Siit runs password resets through Okta, JumpCloud, or Google Workspace, and MFA resets through Okta or JumpCloud, never through the MDM. If Windows sits alongside the Mac fleet, the same lock, wipe, and open actions are available on Microsoft Intune. The practical effect is that whoever picks up the locked-laptop request answers it in the thread it arrived in, instead of opening a second console to find out which laptop it is.

FAQs

How much does Iru cost?

Iru does not publish list pricing, and every product is quote-based on an annual commitment billed annually. Procurement data puts the range at roughly $30 to $80+ per device per year depending on product mix. The number worth negotiating is year two, not year one: ask for a renewal ceiling in writing before signing, and price a multi-year term at purchase rather than at renewal.

How mature is Iru's Windows support?

Less mature than the Apple side, and the gap is measurable rather than vague. Auto Apps patches Windows applications today, but Vulnerability Management is Mac-only with Windows listed as coming soon, so the detection-to-patch loop that makes the security bundle worth buying doesn't close on Windows yet. During the 14-day trial, enroll a Windows machine and check whether vulnerability response fires on it before you count Windows as covered.

Can Iru replace a separate EDR licence?

For a Mac fleet, often yes. Detection and response ship in the same agent as device management, which removes a second install and a second licence. Whether it replaces your EDR standard depends on the rest of the estate: vulnerability management is Mac-only today, so a team with a cross-platform detection standard will still be running two tools.

Does Iru track user activity?

Iru logs administrator activity, not employee behavior. Its change logging gives IT visibility into changes made to configuration and policy, which is change management rather than monitoring. If your works council or employee handbook asks what the MDM can see, the honest answer is device state and configuration history, not keystrokes or browsing.

Is Iru better than Jamf?

Only if you don't have a Mac admin. Iru is the better choice for teams whose IT generalists configure policy rather than write it, and who would rather have EDR included than assembled. Jamf is the better choice if someone on your team maintains Jamf policy, scripts against the API, or needs CIS, NIST, and STIG templates for an auditor, and that person's time is worth more than the licence difference.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.