Mobility & UEM

Intune or Ivanti? Choosing an MDM platform you will still like in three years

The honest comparison, from a partner that runs both in production for Australian government. Where each one wins, and the questions that actually decide it.

CDTS Australia 8 min read

We run Microsoft Intune, Ivanti Neurons for MDM, Jamf Pro and SOTI MobiControl in production. That is deliberate: it means the platform recommendation can follow the requirement rather than the licence agreement.

It also means we get asked this question constantly, usually phrased as “which is better”. That is the wrong question. The right one is “which is better for this environment, with these constraints, and these people running it”.

Here is how we actually answer it.

Where Intune wins

You are already deep in Microsoft. If you hold E3 or E5, Intune is effectively already paid for. That is not a small thing, and pretending otherwise to sell a second platform is one of the ways partners lose trust.

Identity and device need to be one conversation. Conditional access reading real device compliance is the single most valuable control in a modern workplace, and it is tightest when device management and identity live in the same tenancy.

Windows is the centre of gravity. Autopilot, Windows Update for Business and configuration profiles for Windows are simply better developed in Intune than anywhere else.

You want one console for everything. Endpoint, identity, data protection and threat signals in one place has real operational value, even when each individual component is not best-of-breed.

Where Ivanti wins

Mobile is the primary computing platform, not an accessory. Ivanti grew up in mobile — MobileIron did MDM when Microsoft was still shipping ActiveSync policies. That heritage shows in the depth of iOS and Android policy control.

You need PROTECTED-designated hosting. Ivanti Neurons for MDM (PROTECTED) is a specific product designation that matters in Australian government procurement, and there is no substitute for it if your security plan calls for it.

Complex per-app connectivity. Per-app VPN and app tunnelling at scale, especially where apps reach back into on-premises systems, is territory where Ivanti’s tooling is more mature.

You are already on EPMM. The migration path from EPMM to Neurons is well-trodden and does not require wiping devices. Moving to a different vendor entirely is a bigger project than most business cases assume.

The Intune caveats nobody demos

None of these are reasons to avoid Intune. They are reasons to find out before the business case is signed, because each one has either a cost or a capability gap attached, and none of them come up in a standard demo.

Locating an iOS device requires putting it in Lost Mode. On iOS and iPadOS, Intune’s Locate device action requires the device to be supervised and in Lost Mode — and Lost Mode locks the device so the user cannot use it. There is no continuous or real-time location: coordinates are only collected at the moment an administrator triggers the action, held for 24 hours, with a last-known location retained up to seven days.

If your use case is “where is this handset right now” for a field or duty-of-care reason, that is not what this feature does. Android Enterprise corporate-owned devices can be located without Lost Mode, so the gap is iOS-specific — which matters, because iOS is the majority of most Australian government fleets.

Certificate infrastructure is either paid or self-hosted. Microsoft Cloud PKI is not included with Intune. Microsoft’s own documentation states it “requires a subscription in addition to Microsoft Intune Plan 1 or Plan 2” — it is an Intune Suite add-on with its own licence cost.

The alternative is running it yourself: Active Directory Certificate Services, a Network Device Enrollment Service server (domain-joined, in the same forest as the CA, and explicitly not on the CA), the Certificate Connector for Microsoft Intune, and a reverse proxy to publish NDES so devices on the internet can enrol. That is several servers to build, patch, monitor and eventually renew certificates on — infrastructure most organisations moved to Intune specifically to be rid of.

Budget for one or the other. Neither is free, and discovering this after signature is a common and avoidable surprise.

Dynamic group membership is not immediate, and cannot be forced. Intune assignments target Entra ID groups, and dynamic group membership is evaluated by an asynchronous background process. Microsoft’s guidance is that changes are “usually processed within a few hours” but “can take more than 24 hours” depending on tenant size, the number of dynamic groups, the volume of object changes, and rule complexity — Match, Contains and memberOf operators all make it worse.

There is no supported way to trigger processing on demand. The documented workaround is to edit the membership rule by appending a whitespace character.

This matters more than it sounds. If a device needs to land in a group to receive a policy, a certificate or an application, the enrolment experience is gated by group evaluation you do not control. Plan enrolment flows and cutover waves accordingly, and keep dynamic rules simple and efficient — it is a performance decision, not a style one.

Microsoft Tunnel is a server you own, not an appliance you deploy. Microsoft Tunnel Gateway is not a hardened virtual appliance. It is a Linux virtual machine or physical server that you build, running the Tunnel software in Docker CE or Podman containers, secured with a TLS certificate you supply. Microsoft’s prerequisites are explicit that you keep the operating system patched.

You also size and scale it yourself: Microsoft’s own sizing table puts 10,000 devices at three servers and 40,000 devices at eight. That is a fleet of internet-facing Linux servers to build, harden, patch, monitor, certificate-manage and capacity-plan.

Compare that to Ivanti Sentry, which ships as a hardened virtual appliance with a vendor-maintained image. Neither model is wrong, but they are very different operational commitments, and only one of them appears on a licence schedule.

The Ivanti caveats, for balance

It would be a poor comparison if only one side had caveats.

It is a separate licence and a separate relationship. If you hold E3 or E5, Intune is already paid for. Ivanti is net-new spend that has to be justified on capability, and the business case has to survive somebody pointing at the licence you already own.

There is still infrastructure for some scenarios. Sentry and connectors are appliances rather than servers you build, but on-premises integrations still mean components to deploy, monitor and keep current.

Windows management is not where it is strongest. For a Windows-heavy estate wanting Autopilot and Windows Update for Business, Intune is the more natural answer.

The local talent pool is smaller. There are more Australian engineers who know Intune than who know Ivanti well. If you intend to operate it in-house, that is a genuine constraint — and it is one of the reasons organisations run it as a managed service.

Where the comparison usually goes wrong

Feature-matrix bake-offs. Both platforms will tick almost every row. The matrix tells you nothing about which one your team will operate well, which is what actually determines the outcome.

Ignoring the operating model. The platform is maybe a third of the decision. The rest is: who runs it, what happens when a certificate expires, who tests the September iOS release, and who is accountable when enrolment breaks. A platform nobody owns fails identically regardless of the badge.

Counting licence cost only. The cheaper licence frequently costs more once you count the effort to operate it, the integration work, and the consulting you will buy anyway.

Assuming you must pick one. Plenty of environments run Intune for Windows and Ivanti or Jamf for mobile and Apple. That is a legitimate architecture, not a failure of decisiveness — as long as somebody owns the joins.

The questions that actually decide it

Work through these before you look at a single feature list:

  1. What is your compliance requirement, stated precisely? If your security plan names a PROTECTED-designated platform, the decision is largely made.
  2. What proportion of your fleet is mobile versus desktop? Mobile-dominant fleets weight differently.
  3. What are you already licensed for? Not what you could buy — what you have already paid for.
  4. Do you need to locate iOS devices without locking them? If yes, understand the Lost Mode constraint before it becomes a requirement you cannot meet.
  5. Who is paying for the certificate infrastructure? Cloud PKI licence, or servers you build and patch. Decide now.
  6. Who will run the VPN gateway? An appliance, or a fleet of Linux servers you harden and scale.
  7. Who will operate it day to day, and how many of them are there? A two-person team and a twenty-person team should not choose the same way.
  8. What does your identity platform look like? If it is Entra ID, the gravitational pull toward Intune is real and worth respecting.
  9. What does migration cost if you are wrong? Platforms are stickier than anyone admits at signature. Weight the reversibility.

What we would say if you asked us cold

If you are a Microsoft-centric organisation with a mixed Windows and mobile fleet and no specific PROTECTED requirement, start with Intune. You have probably already bought it.

If mobile is the business — field teams, deployed personnel, devices as the primary system — or your security plan names a PROTECTED-designated platform, Ivanti Neurons earns its place.

If you have a significant Apple estate, neither answer is complete without deciding how Macs and iPads are managed, and that frequently means Jamf alongside whatever else you run.

And if you already have a platform that broadly works, the highest-return project is almost never replacing it. It is operating the one you have properly.


We hold partnerships across all of these specifically so this conversation can be honest. If you want it applied to your environment rather than in the abstract, that is what the assessment does.

The Intune behaviours described here are drawn from Microsoft’s own published documentation on the Locate device action, Microsoft Cloud PKI, dynamic group processing and Microsoft Tunnel prerequisites. Platform behaviour changes — check the current documentation before making a decision on it.

Next step

Let’s talk about your environment

Tell us what you are running today and where it hurts. We will give you a straight answer on whether we are the right fit, and what we would look at first.