RichnTech — Device Security, Simplified.
Home About Rich Content Hub MDM Tools & Gear The MDM Showdown DMMM Assessment BYOD Policy Builder Contact
Device Security 2026

Your Devices
Are Unmanaged.
Let’s Fix That.

Phones get lost. Laptops leave the building. Kids bypass every setting you thought was locked. Most people — and most businesses — have zero control over their devices. That ends here.

73%Of breaches involve
endpoint devices
67%Of BYOD companies
have no policy
$4.5MAvg. data breach
cost in 2024
82%Of parents don’t use
device management
Lost Device Data Leaks Shadow IT Apps Unpatched Endpoints BYOD Policy Gaps Child Screen Time Bypass Default Admin Credentials Bluetooth Relay Attacks Rogue Wi-Fi Enrollment Lost Device Data Leaks Shadow IT Apps Unpatched Endpoints BYOD Policy Gaps Child Screen Time Bypass Default Admin Credentials Bluetooth Relay Attacks Rogue Wi-Fi Enrollment
// What We Cover

Five Pillars of Device Security

From locking down your own phone to managing a fleet of employee devices — RichnTech covers every layer.

Lock It Down

Device security basics — remote wipe, biometrics, encryption, auto-updates. The stuff everyone skips.

BYOD or Bust

Personal devices at work without a policy is a lawsuit waiting to happen. Build one in minutes.

Parent Mode

Screen Time, Family Link, app restrictions, content filtering — actually manage your kid’s devices.

The DMMM

The Device Management Maturity Model. A framework for knowing where you stand — and where you need to be.

MDM Reviews

Jamf, Hexnode, Mosyle, Intune, Apple Business Essentials — honest reviews, real comparisons.

Ph.D. — IT & Innovation
MBA
3PCRM Practitioner
DMMM Creator
About the Author

Ph.D. IT Researcher.
Device Security
Specialist.

I built RichnTech because I saw a gap — plenty of MDM content for enterprise IT teams, but nothing honest and practical for small businesses, remote workers, and parents trying to manage the devices in their lives.

Ph.D. — IT & Innovation Management
MBA — Business & Strategy
3PCRM Practitioner (Third-Party Cyber Risk)
Creator of the DMMM Framework
Independent Researcher
rich_durfee.profile
$ whoami
> Rich Durfee — Ph.D., MBA
$ cat specialty.txt
> Mobile Device Management
> BYOD Policy & Endpoint Security
> Family Device Management
$ cat framework.txt
> DMMM — Device Management Maturity Model
$ cat mission.txt
> Device security, simplified.
> If it’s not managed, it’s exposed.
> _
Ph.D. ITMBA3PCRMDMMMMDM
Why Device Management

My background is in IT innovation and third-party cyber risk management. But the more I worked in enterprise security, the more I noticed: the same device management problems plaguing Fortune 500 companies were destroying small businesses and families too — and nobody was translating the solutions into plain language.

RichnTech exists to fix that. Every MDM recommendation is based on actual security merit. Every BYOD template is built from real-world policy frameworks. Every parental control walkthrough is tested on actual devices. No fluff. No sponsored rankings. Just what works.

The DMMM Approach

I created the Device Management Maturity Model (DMMM) because most people — and most organizations — have no idea where they stand when it comes to managing their devices. The DMMM gives you a framework: five levels from ad-hoc to fully automated, with clear benchmarks at each stage.

Whether you’re a business owner who just realized your employees’ phones have access to company data, or a parent who just found out your kid disabled Screen Time — the DMMM tells you exactly where you are and what to do next.

// RichnTech Content Hub

Device Security Knowledge Base

Everything you need to know about managing, securing, and controlling devices — across five content pillars.

Not Sure Where to Start?

Take the DMMM Self-Assessment and find out exactly where your device management stands — in under 3 minutes.

// MDM Tools & Endpoint Gear

The MDM Toolkit.

MDM platforms for businesses, parental control tools for families, and the endpoint security gear that supports managed environments. Every recommendation is vetted.

MDM Platforms

Software that lets you enroll, configure, monitor, and enforce policies on managed devices — phones, tablets, and laptops.

Jamf Now
Best-in-class Apple device management for small businesses. Simple enrollment, policy push, app distribution.
From $4/device/mo Apple only
Learn More
Hexnode
Cross-platform MDM — Apple, Android, Windows. Kiosk mode, geofencing, compliance policies. Strong for mixed fleets.
From $1/device/mo Cross-platform
Learn More
Mosyle
Apple-focused MDM with zero-touch deployment, automated patching, and identity management built in.
Free tier available Apple only
Learn More
Microsoft Intune
Enterprise-grade MDM included with Microsoft 365 Business Premium. Deep Windows integration, conditional access.
Included w/ M365 Cross-platform
Learn More
Google Endpoint Mgmt
Built into Google Workspace. Basic device management, screen lock enforcement, remote wipe. Often overlooked.
Included w/ Workspace Cross-platform
Learn More
Apple Business Essentials
Apple’s own MDM for small businesses. Device management, storage, and AppleCare in one subscription.
From $2.99/mo Apple only
Learn More
Family Device Management

Parental control platforms that manage screen time, content filtering, app restrictions, and location tracking for kids’ devices.

Bark
AI-powered content monitoring across 30+ apps. Alerts for cyberbullying, depression signals, and explicit content.
From $5/mo iOS + Android
View on Amazon
Qustodio
Cross-device parental controls — screen time limits, web filtering, app blocking, location tracking, panic button.
From $5/mo All platforms
View on Amazon
Circle by Disney
Router-level content filtering and screen time management. Controls every device on your network, including IoT.
~$30 + subscription Network-level
View on Amazon
Endpoint Security Gear

Physical hardware that strengthens the security of managed devices — authentication keys, secure routers, and endpoint protection that pairs with MDM platforms.

YubiKey 5 NFC
Hardware MFA key. Pairs with MDM enrollment for phishing-resistant authentication on managed devices. FIDO2 + U2F.
~$50 USB-A + NFC
View on Amazon
YubiKey 5C NFC
Same hardware MFA, USB-C form factor. Essential for managed MacBooks and modern laptops with enforced MFA policies.
~$55 USB-C + NFC
View on Amazon
TP-Link Deco XE75
Wi-Fi 6E mesh system with built-in network segmentation. Isolate managed devices from guest and IoT traffic. WPA3.
~$250 Wi-Fi 6E Mesh
View on Amazon
Bitwarden
Open-source password manager. Integrates with MDM-deployed browser profiles for managed credential policies across devices.
Free / $10/yr All platforms
Learn More
DMMM Self-Assessment

Where Does Your Device Management Maturity Fall?

Check off what you currently have in place across five maturity dimensions. Get your DMMM level instantly.

// The Five Levels
01
Level 1 — Ad Hoc
No visibility. No policies. Devices connect to everything and nobody tracks what’s on them. You don’t know what you don’t know.
02
Level 2 — Reactive
You know devices exist, but you’re manually checking things. Password requirements are “suggested.” Updates happen when someone remembers.
03
Level 3 — Defined
Written policies exist. An MDM platform is deployed. Devices are enrolled. But enforcement is inconsistent and gaps remain.
04
Level 4 — Managed
Policies are enforced automatically. Compliance is monitored. Non-compliant devices are flagged or quarantined. You have real visibility.
05
Level 5 — Optimized
Fully automated. Zero-touch deployment. Continuous compliance. Threat response is immediate. The DMMM gold standard.
📱
Device Inventory & Visibility
0 / 20
🔐
Security Policies & Enforcement
0 / 20
🔄
Updates & Patch Management
0 / 20
📋
BYOD & Offboarding
0 / 20
🚨
Incident Response & Remote Actions
0 / 20
Your DMMM Score
0/100
Check items above to begin
BYOD Policy Builder

Build Your BYOD Policy in 5 Questions

Answer a few questions about your business and get a customized BYOD policy outline you can implement immediately.

QUESTION 1 OF 5
How many employees use personal devices for work?
RichnTech Blog

The MDM Showdown

Apple’s free tools vs. Jamf vs. Kandji vs. Intune vs. NinjaOne vs. Android — what’s actually free, what’s worth paying for, and what’s right for you. Click a platform below to get the breakdown.

Here’s the truth most MDM comparison articles won’t tell you: you might already be paying for device management and not using it. Apple Business Manager is free. Google Endpoint Management is included with Workspace. Microsoft Intune is bundled with certain 365 plans. Before you drop $5/device/month on a third-party MDM, you need to know what you already have.

// Pick Your Fighter

Click any platform to see the full breakdown — what it costs, what it does, who it’s for, and what it’s missing.

Apple Free
ABM + ABE
Jamf
Now / Pro / Business
Kandji
Apple-First MDM
Intune
Microsoft 365
NinjaOne
RMM + MDM
Android Free
Built-In Tools

Apple Business Manager + Business Essentials

ABM: FREE ABE: From $2.99/mo Apple only

Most people don’t realize Apple gives you two separate products — and one is completely free. Apple Business Manager (ABM) is a free web portal for device inventory, Automated Device Enrollment (ADE), Managed Apple IDs, and bulk app purchasing. It’s the foundation every Apple MDM connects to. You should sign up regardless of what MDM you choose.

Apple Business Essentials (ABE) is Apple’s actual MDM layer, starting at $2.99/month per device. It adds remote configuration, policy enforcement, password rules, FileVault, remote lock/wipe, and app distribution — plus bundled iCloud storage and AppleCare+ support that no third-party MDM includes.

The catch? ABE only manages Apple devices. No Android, no Windows. It’s designed for small businesses under 500 employees running an all-Apple fleet. If that’s you, this is a serious option most people overlook.

Strengths

  • ABM is completely free — no catch
  • Zero-touch deployment via ADE
  • AppleCare+ and iCloud bundled with ABE
  • Managed Apple IDs with SSO support
  • Declarative management for real-time compliance

Limitations

  • Apple devices only — no cross-platform
  • ABE lacks advanced conditional access
  • No staged app rollouts or granular controls
  • No built-in MFA enforcement
  • Not suitable for fleets over 500 devices

// RichnTech Verdict

If you’re a small business running all Apple and you haven’t signed up for ABM yet, you’re leaving free infrastructure on the table. ABE is worth it for teams under 50 who want simplicity. Beyond that, you’ll likely outgrow it.

Jamf — Now / Pro / Business

Now: $4/device/mo Pro: ~$3.67/device/mo Business: ~$13.65/device/mo Apple only

Jamf is the OG of Apple device management. It’s been around longer than any competitor and has the deepest Apple integration. Three tiers: Jamf Now (simplified, small teams), Jamf Pro (full MDM with scripting and smart groups), and Jamf Business (Pro + identity + endpoint security).

Where Jamf dominates is customization. Extension attributes, smart groups, custom scripts, and deep API access let you build exactly the workflows you need. It’s un-opinionated by design — giving you tools, not opinions. That’s both its strength and its learning curve compared to Kandji’s no-code approach.

Jamf Pro also has the most mature Self Service app, letting employees install approved apps themselves without bugging IT. For organizations scaling past 100 Apple devices with complex compliance needs, Jamf Pro remains the benchmark.

Strengths

  • Deepest Apple ecosystem integration
  • Smart groups and extension attributes
  • Mature Self Service app for end users
  • Full scripting and API automation
  • Proven at enterprise scale (100K+ devices)

Limitations

  • Apple only — no Windows or Android
  • Steeper learning curve than Kandji
  • Business tier gets expensive fast
  • Interface feels dated vs. newer MDMs
  • Requires technical expertise to configure

// RichnTech Verdict

If you’re an Apple-only shop with a real IT team and need granular control, Jamf Pro is still the gold standard. For small teams who don’t need scripting, Jamf Now is simpler but pricier per device than Kandji’s entry tier.

Kandji

iOS: From $1.60/device/mo macOS: From $3.20/device/mo Apple-first

Kandji was built by people who were tired of configuring Jamf. It’s the no-code challenger — over 200 prebuilt automations that handle common MDM tasks like password policies, Wi-Fi settings, and app deployment without custom scripting. If Jamf gives you a toolbox, Kandji gives you a pre-assembled kit.

The platform handles zero-touch deployment, automated compliance (with built-in CIS, NIST, and SOC 2 templates), and patch management for macOS and third-party apps. It’s popular with mid-market companies and lean IT teams that don’t have dedicated Apple admins.

The trade-off is flexibility. Kandji’s “opinionated” design means fewer customization options. If you need bespoke configurations or deep scripting, you’ll hit walls. Pricing also scales separately for iOS vs. macOS, and add-ons like EDR can nearly double costs.

Strengths

  • 200+ prebuilt automations — no scripting
  • Built-in compliance templates (CIS, NIST, SOC 2)
  • Clean, modern interface
  • Fast deployment — often under a week
  • Free migration support from Jamf

Limitations

  • Less customizable than Jamf for complex setups
  • iOS and macOS priced separately
  • EDR/vulnerability add-ons nearly double cost
  • Newer — some third-party integrations lag
  • Custom pricing makes budgeting harder

// RichnTech Verdict

Kandji is the best option for lean IT teams who want compliance and automation without a Jamf-level learning curve. Under 500 Apple devices and don’t need deep scripting? Kandji likely saves you both time and money.

Microsoft Intune

Included w/ M365 Business Premium Standalone: ~$8/user/mo Cross-platform

If your company already pays for Microsoft 365 Business Premium, you already have Intune — and you’re probably not using it. That’s the hidden MDM most businesses overlook. Intune manages Windows, macOS, iOS, and Android from one console, making it the default cross-platform option for Microsoft shops.

Intune’s killer feature is conditional access — blocking non-compliant devices from company email, SharePoint, or Teams automatically. Combined with Azure AD, it creates a zero-trust posture that standalone Apple MDMs can’t match without bolt-on identity products.

The downside? Intune’s Apple management is functional but not deep. It relies on ABM for enrollment, and macOS capabilities lag behind Jamf and Kandji. The admin console is also notoriously complex — it’s a Microsoft product built for Microsoft environments.

Strengths

  • Included with M365 Business Premium
  • True cross-platform: Windows, macOS, iOS, Android
  • Conditional access with Azure AD
  • Deep Windows management unmatched
  • Compliance policies tied to identity

Limitations

  • Apple/macOS management weaker than Jamf/Kandji
  • Admin console has a steep learning curve
  • Standalone pricing expensive per-user
  • Heavily Microsoft-ecosystem dependent
  • Configuration overwhelming without experience

// RichnTech Verdict

If you’re a Microsoft 365 shop with a mixed fleet, Intune is the obvious first move — you’re already paying for it. For Apple-heavy environments, pair Intune with Jamf or Kandji for the best of both worlds.

NinjaOne

MDM: $1.50–$3.75/device/mo Add-on to base RMM iOS + Android + macOS

NinjaOne isn’t an MDM company — it’s an RMM company that added MDM. That distinction matters. If you’re already using NinjaOne for endpoint monitoring, patch management, and remote access, adding mobile device management to the same console makes life easier.

NinjaOne’s MDM handles iOS, Android, and macOS enrollment, policy enforcement, remote lock/wipe, passcode rules, kiosk mode, and zero-touch deployment. It inherits NinjaOne’s strong automation engine — policy resyncs, compliance checks, and patching run without manual triggers.

The catch: MDM is an add-on, not standalone. You need the base NinjaOne platform first. And critically, NinjaOne MDM does not manage Windows devices — that requires the separate RMM module. For pure mobile device management, dedicated MDMs offer more depth.

Strengths

  • Unified console — RMM + MDM together
  • Strong automation from RMM side
  • Mature remote access tools
  • 14-day free trial, free onboarding
  • Android + iOS + macOS support

Limitations

  • MDM is add-on — requires base platform
  • Windows needs separate RMM module
  • Less deep than dedicated Apple MDMs
  • Pricing expensive at small scale
  • RMM-first, not purpose-built for MDM

// RichnTech Verdict

NinjaOne makes sense if you’re already in their ecosystem for RMM/patching and want mobile management in the same pane of glass. If MDM is your primary need, a dedicated platform gives you more for less.

Android Built-In Device Management

Work Profile: FREE Google Endpoint Mgmt: Included w/ Workspace Android only

Android’s built-in device management is more capable than most people realize — and Google Workspace customers get endpoint management included. Android Enterprise provides Work Profiles that cryptographically separate personal and work data, arguably more elegant than Apple’s BYOD approach.

Google Endpoint Management (included with Workspace Business Starter+) lets admins enforce screen locks, require encryption, remotely wipe devices, block compromised devices, and manage app deployment. Work Profiles mean you can selectively wipe only the work container when an employee leaves — personal data stays untouched.

Android Zero-Touch Enrollment mirrors Apple’s ADE — devices from authorized resellers auto-enroll on first boot. The difference: Android supports this across dozens of manufacturers, not just one.

Strengths

  • Work Profiles provide true data separation — free
  • Google Endpoint Mgmt included with Workspace
  • Zero-Touch enrollment across all major OEMs
  • Selective wipe for BYOD offboarding
  • Works with most third-party MDMs too

Limitations

  • Fragmented OEM support — devices aren’t equal
  • Google Endpoint Mgmt basic vs. Intune
  • No macOS or Windows management
  • Samsung Knox adds features but Samsung-only
  • Enterprise features vary by manufacturer

// RichnTech Verdict

If your team uses Google Workspace and Android, you already have legitimate device management included. Work Profiles are underrated for BYOD. For deeper control or mixed fleets, pair with Hexnode or Intune.

// The Cheat Sheet
PLATFORMCOSTAPPLEANDROIDWINDOWSBEST FOR
Apple ABMFreeFoundation for all Apple MDM
Apple ABE$2.99+/moSmall Apple-only teams
Jamf Pro~$3.67/dev/moApple power users & enterprise
Kandji$1.60+/dev/moLean IT teams wanting automation
IntuneIncl. w/ M365Microsoft shops, mixed fleets
NinjaOne$1.50–3.75/dev🔧MSPs using NinjaOne RMM
Android FreeFreeGoogle Workspace + Android

✅ Full support   ⚡ Beta/limited   🔧 Via separate module   ❌ Not supported

The Bottom Line

There is no single “best” MDM. The right platform depends on your fleet (Apple-only vs. mixed), your team (dedicated IT vs. lean ops), your existing subscriptions (M365 vs. Google Workspace), and your compliance requirements.

But here’s what I tell everyone: check what you already have before you buy anything new. Apple Business Manager is free. Google Endpoint Management is included. Intune might already be in your M365 plan. Start there. Then upgrade when you hit the limits — not before.

// Get in Touch

Got Questions?
I Actually Respond.

MDM questions, BYOD policy help, DMMM consulting, or content collaboration — reach out.

Email Rich

MDM questions, consulting, or partnerships.

admin@richntech.com
Instagram

Daily device security tips, MDM reviews, and BYOD content.

@richntech.daily

Resources

For enterprise MDM guidance, check the NIST SP 800-124 (Guidelines for Managing the Security of Mobile Devices) and CIS Benchmarks for iOS, Android, and Windows device hardening.

For parental controls research, the Family Online Safety Institute (FOSI) and Common Sense Media maintain regularly updated device management guides for families.