Our renewals hit in March and I’m weighing one platform vs best‑of‑breed for about 520 laptops and 160 iPads; has anyone moved to Intune/Defender or JumpCloud + CrowdStrike and lowered TCO? I’m buying for a 300‑person company and care as much about admin hours and surprise add‑ons as per‑device pricing.
With March coming up, I’d spin a 30‑day pilot: enroll about 50 of the 520 laptops and about 20 of the 160 iPads in Intune/Defender and time enrollment, app push, and autopatch so you’ve got real admin‑hour data. The gotcha that bit me was Microsoft licensing creep — — so have your CSP send a SKU matrix and sanity‑check against Licenses available for Microsoft Intune - Microsoft Intune | Microsoft Learn before you model TCO. If you tried JumpCloud + CrowdStrike, how did patch cadence and iPadOS MDM API coverage compare?
@jbrown38’s pilot idea is solid, but the gotcha is the “surprise add‑ons”: Intune + Defender often needs Entra ID P1/P2 and Defender for Endpoint P2 to cover those 160 iPads, while JumpCloud + CrowdStrike will cost admin time on macOS for system extension approvals and sensor updates. Before March, get co‑term quotes that include those pieces and run a zero‑touch ABM/ADE test with 5 iPads and 5 laptops to time true setup vs. your 520 fleet. Are the laptops mostly Windows or a Mac‑heavy mix?
I’d tackle the ‘surprise add‑ons’ by scoping mobile to MDM‑only and pricing EDR just for the 520 laptops; get both stacks to quote a flat, all‑in per‑user that includes compliance/CA. Then time three workflows — new hire, lost device, offboarding — and put those hours next to the license numbers. Are the iPads high‑risk users or mostly kiosk/field, because that decides whether mobile EDR is worth it?
Quick tip: in your pilot, pipe alerts from both stacks into the same queue and time a week of triage; when we moved to Intune/Defender, turning on built‑in suppression and CA baselines cut admin hours more than the license delta. @jbrown38 is on the right track — are the iPads kiosk/field so you can keep them MDM‑only?
In your pilot, run a full day‑2 drill: replace a lost laptop, re‑issue a tablet, and offboard a user end‑to‑end, timing from ticket to compliant device. Ask both vendors for a written SOW that includes ‘co‑term/true‑up’, ‘iOS/macOS system extension approvals’, and who owns the Apple Push certs — tiny checkbox now, migraine later. Do you already have M365 E3/E5 or Google Workspace in place, since that can swing TCO and admin hours?
If most of those 520 are Windows, Intune/Defender with “Windows Autopatch” cut our patching toil by about 6–8 hrs/month and kept us inside Entra/Intune instead of juggling agents: https://learn.microsoft.com/windows/deployment/windows-autopatch/windows-autopatch-overview. Small gotcha: macOS baselines in Intune (PPPC, system extensions, FileVault escrow) are still fiddly — — so if your fleet skews Mac, JumpCloud + CrowdStrike can feel smoother there. @OP what’s your Windows vs Mac split on the laptops?