Iru: In-Depth Review & Analysis

Iru (formerly Kandji) combines device management, patching, EDR, passwordless identity and compliance automation in one console. We think it is a strong fit for lean IT teams running Mac and Windows fleets.

Last updated on Sep 17, 2026
Craig MacAlpine Technical Review by Craig MacAlpine
Iru Logo
5.0
Editor's Score

Expert Insights Verdict

If your fleet is mostly Mac or you are frustrated with Intune, looking beyond an Apple-only MDM, or managing identity and compliance through separate tools, we recommend Iru. Its strength is the routine work it takes off the IT team’s hands. The agent checks device configurations every 15 minutes, Auto Apps handles patching for 261 Mac and 240 Windows applications, and device and identity data feed compliance evidence automatically. Bringing these functions together reduces the work of maintaining separate systems. Windows management has fewer options than Mac management. For EDR, behavioral detection on Windows is planned for early 2027. Android currently supports company-owned devices that allow personal use. Best for: Organizations running Mac and Windows with a lean IT team that want device management, patching, identity and compliance in one console; a weaker fit for buyers requiring on-premises management or extensive configuration possibilities for Windows.

Strengths
The agent checks configuration every 15 minutes, and continuous enforcement reinstalls required apps if users remove them.
Auto Apps handles patching for supported software, including applications the admin never deployed, with Mac privacy permissions pre-packaged.
Assignment Maps target deployments using the groups in your identity provider or device attributes, and a per-user view shows why a device is or is not getting something.
One agent covers management, EDR and vulnerability response on Mac and Windows; adding EDR is one Library Item.
Support is included and is fully staffed by former IT practitioners.
Identity configuration is versioned with one-click rollback, and authentication policies check device posture from Iru Access at every sign-in.
Compliance drafts controls for your organization, tracks evidence between audits, and includes unlimited frameworks in one price.
Cautions
Windows management has fewer options than Mac management. Windows behavioral EDR is scheduled for early 2027 and is not available today.
Android covers the COPE model only; BYOD work profiles, fully managed and dedicated devices remain on the roadmap.
Cloud-only: organizations requiring on-premises management are out of scope.
Compliance has no vendor risk management, supplier assessment or risk scoring.

Fast Facts

  • Headquarters: Miami, FL
  • Founded: 2018 as Kandji; rebranded Iru in 2025
  • Ownership: Private, venture-backed; $300M raised to date
  • Certifications: SOC 2 Type II, ISO 27001, ISO 42001
  • Delivery: Cloud SaaS, with US and EU tenant regions

Iru’s Approach

Iru (formerly Kandji) puts device management, EDR, vulnerability management, passwordless identity and compliance automation in one data model and console. As Kandji, Iru spent seven years building Apple device management and security tooling. It now covers macOS, iOS, Windows and Android, with the broadest set of controls still available on Apple devices.

Their core product, device management, is where most customers still start today. The basic idea is simple: you tell Iru what a device should look like, and the agent checks its configuration every 15 minutes. If a user removes an app set to continuous enforcement, Iru reinstalls it at check-in without anyone raising a ticket. The platform enforces app updates, scans for signs of malicious activity and applies policies by device and user.

An endpoint agent combines management, EDR, and vulnerability management on both Mac and Windows. iOS, Apple TV, and Android are managed only through device management APIs, without a local agent.

The Library holds the apps, settings and scripts admins deploy. Blueprints combine these into a device’s configuration, and Assignment Maps tailor it by device or user. This lets teams set a common baseline and handle differences within it.

Iru’s AI helps admins review configuration choices. For example, it can read all 37 settings of a Windows Update policy, propose a configuration and explain each change. We like having the explanation alongside the proposed settings: it makes the recommendation easier to assess. Iru’s AI can also draft compliance policies and prepare answers to incoming security questionnaires for a human to review.

Market Position

Iru brings device management, endpoint security, identity and compliance into one platform. Its endpoint, identity and compliance products can also be bought separately: device management integrates with third-party identity providers, while compliance can work with another MDM.

In device management, we see Iru’s clearest competitive case in Mac-led fleets. For organizations frustrated by Intune’s Windows-focused console or slow policy updates, Blueprints and 15-minute configuration checks address how policies are organized and enforced. For teams using Jamf or Mosyle, a growing Windows fleet creates a reason to look beyond Apple-only management. Iru brings those devices into the same console. Workspace ONE, Intune, JumpCloud and Rippling are other competitors in mixed fleets. Iru is also a popular choice for organizations that prioritize automation and user experience over the deeper controls that Jamf or Intune offer.

Integrated EDR and vulnerability management gives organizations already using Iru for device management another opportunity to consolidate tools. We would compare detection and response coverage before replacing a dedicated product such as CrowdStrike, particularly on Windows, where behavioral detection is not yet available. Iru’s optional threat protection tooling is aimed at IT teams managing security alongside their other responsibilities. It exports telemetry to a customer’s SIEM and offers a raw telemetry API for teams that do run a security operations center.

Against separate workforce identity and compliance automation providers, Iru offers one vendor, with device and identity data feeding compliance evidence. Its identity product targets companies that want device-aware sign-in policies with fully passwordless authentication without the complexity of Okta; it is less suited to teams that need Okta’s full depth. In compliance, Iru competes with Vanta and Drata, combining AI-assisted controls, evidence collection, and policies tailored to the organization.

Iru is delivered as cloud SaaS, with US and EU tenant regions.

Iru sells directly, is building a reseller channel, and has launched an MSP program. MSPs can create parent and child tenants with itemized billing based on device counts and product use. MSPs choose per tenant between a fully managed model, where the MSP owns client support and Iru routes inquiries back, and a reseller model, where end clients can reach Iru directly.

Use Cases

Managing a Mixed Endpoint Fleet From One Console

Mac, Windows, iPhone, iPad, Apple TV, Vision Pro and Android devices appear in a single list with saved views, tags for static grouping and device actions such as lock, erase and recovery-key access where supported. Apple Business Manager integrates directly for automated enrollment and app licensing.

Android support currently covers the company-owned, personally-enabled (COPE) model only: company devices that also allow personal use. BYOD work profiles are next on the roadmap, followed by fully managed and dedicated devices. Windows management, launched in 2025, mirrors the Mac experience with fewer options; Blueprint templates and pre/post-install scripts remain Mac-only today.

One console across the fleet: saved views split devices into Mac, Windows, mobile, and Android.
One console across the fleet: saved views split devices into Mac, Windows, mobile, and Android.
Library restrictions filtered to Vision Pro: only settings applicable to the platform remain visible.
Library restrictions filtered to Vision Pro: only settings applicable to the platform remain visible.

Application and OS Patching Without Touching Devices

Auto Apps covers 261 Mac and 240 Windows applications. Iru reports that a new Zoom release reaches its catalog within two to four hours.

What we particularly like is how Iru balances update enforcement with the person using the device. A forced update during a presentation or customer call is a real disruption. Iru lets users defer an update for one hour, up to 24 times, before a five-minute countdown forces it through. That gives someone delivering a presentation room to postpone the interruption, while IT retains a firm deadline for bringing the application up to date. Closed applications update automatically.

Deployment modes are continuous enforcement, which reinstalls an app at check-in if removed; self-service; and update-only, which patches software the admin never deployed. Paywalled installers such as CrowdStrike are excluded from the catalog, so some applications still need a separate deployment and maintenance process using a Custom App.

macOS updates use Apple’s declarative device management with the same enforcement options and phased rollouts. Windows OS updates use Windows device management protocols. Vulnerability management ties in: detections are matched against the catalog, and a severity-triggered response item automatically remediates any vulnerable app or OS that Iru can patch, whether or not Iru deployed it.

The Auto Apps catalog, filtered to Mac; 261 Mac and 240 Windows titles (September 2026).
The Auto Apps catalog, filtered to Mac; 261 Mac and 240 Windows titles (September 2026).
Per-app deployment modes: continuously enforce, install on demand from Self Service, or update only.
Per-app deployment modes: continuously enforce, install on demand from Self Service, or update only.
Rolling version enforcement for macOS 26 Tahoe, with the enforcement schedule computed from release dates.
Rolling version enforcement for macOS 26 Tahoe, with the enforcement schedule computed from release dates.

Adding EDR Without a Dedicated Security Team

EDR ships in the same agent as device management and is deployed by adding a Library Item to a Blueprint. The controls cover malware, potentially unwanted programs (PUPs), malicious and suspicious behavior, with coverage differing between Mac and Windows.

On Mac, admins can choose detect mode, which surfaces findings, or protect mode, which quarantines files and kills the associated processes automatically. Mac devices can also be partially or fully network-isolated, and detections use Apple’s Endpoint Security API. On Windows, threat protection is file-based; behavioral detection, automatic quarantine and device isolation are scheduled for early 2027.

AI-generated summaries show recommended next steps for each detection. The summaries help explain an alert, but the team still needs someone responsible for acting on it.

A quarantined detection in protect mode: file details, malware family, and the AI detection summary.
A quarantined detection in protect mode: file details, malware family, and the AI detection summary.

Targeting Deployments by Who the User Is

Every device belongs to exactly one Blueprint. Assignment Maps apply conditional rules within it. A foundation column deploys to every device, then if/else-if blocks target device attributes, tags or identity-provider data, including departments, groups and job titles synced over SCIM from Okta, Entra ID or Iru’s identity product. For example, Finance users can receive particular apps, while devices tagged for shared use receive tighter restrictions.

Everything in the Library can be dragged into a block. Where rules conflict, the block furthest to the right takes precedence, so an enforced install overrides a self-service offer for the users that block targets. A per-user simulation view shows exactly what any individual’s device receives and why. We found this a useful way to understand a deployment without tracing every rule manually.

An Assignment Map flowing left to right: foundation items, then department-conditional blocks.
An Assignment Map flowing left to right: foundation items, then department-conditional blocks.
Device lookup in an Assignment Map: the logic trail shows why an item does or does not apply.
Device lookup in an Assignment Map: the logic trail shows why an item does or does not apply.

Passwordless Identity Across the App Estate

Workforce Identity uses passwordless sign-in with a passkey held in the device’s Secure Enclave on Mac or TPM 2.0 chip on Windows, unlocked by the user’s fingerprint or face.

Iru Access, its authenticator app, runs on Mac, Windows and iOS, with Android coming. It ties passkeys to managed devices and serves as a launchpad for employees to access company apps. It can be deployed by Iru or using another MDM. YubiKeys and unmanaged passkeys can also be allowed as an alternative to Iru Access.

Inbound user data comes from an HRIS connection, from a directory integration, or a CSV import. Outbound, Iru provisions and de-provisions accounts in downstream applications over SCIM.

Around 215 application templates cover SAML and OIDC apps. Custom connections are also supported, and every change to an app is versioned. Admins can edit in the interface or in code, compare versions side by side, and roll back by setting an earlier version as current.

Authentication policies run at every sign-in and check the device: System Integrity Protection, sealed system volume, FileVault and firewall on Mac; BitLocker, TPM, Defender, Secure Boot and OS build on Windows. Device posture data comes from Iru Access.

Users can add a new authenticator themselves by bringing both devices within Bluetooth range, entering a six-digit code and approving with a fingerprint or face on each device. Iru Access then approves the pairing and logs the cryptographic lineage of the newly minted passkey. A lost phone can be suspended and reinstated by the user from another authenticator.

An authentication policy evaluating device posture at sign-in: Mac and Windows integrity checks side by side.
An authentication policy evaluating device posture at sign-in: Mac and Windows integrity checks side by side.
Application config as code: a diffed change to a Google Workspace SSO integration, one click from rollback.
Application config as code: a diffed change to a Google Workspace SSO integration, one click from rollback.

Compliance

You can start a compliance framework in four ways: let AI draft controls for your organization from your industry, size and technology stack; migrate an existing program from a compliance automation vendor like Vanta, Drata, or Secureframe; import a prepared CSV; or start from scratch. Iru says AI-generated controls take about fifteen minutes. Each control is then split into a checklist of tasks with an owner, due date and completion status.

Evidence comes from connected sources or manual upload. Iru identifies what a file is, checks it for an expiration date and matches it to the jobs it satisfies. Adaptive compliance tracks changes in your environment or policies between audits and suggests updates to controls and actions, with a person approving each one. Frameworks cover SOC 2, ISO 27001, ISO 27701, ISO 42001, GDPR, HIPAA, NIST 800-53, NIST 800-171, NIST CSF 2.0, CMMC and Cyber Essentials.

Iru says it builds additional frameworks customers need within several weeks. Policy management drafts policies, assigns them and tracks who has accepted. The Trust Center publishes your controls and documents, gates sensitive ones behind an NDA, and drafts answers to questionnaires customers send you. It does not send questionnaires to your own suppliers, and does not provide vendor risk management and risk scoring.

The framework catalog: SOC 2, ISO 27001, HIPAA, GDPR, both NIST frameworks, CMMC, and the newly released Cyber Essentials.
The framework catalog: SOC 2, ISO 27001, HIPAA, GDPR, both NIST frameworks, CMMC, and the newly released Cyber Essentials.
AI generating tailored controls for a GDPR program: control language customized to the organization.
AI generating tailored controls for a GDPR program: control language customized to the organization.
Evidence handling: an uploaded artifact is typed, checked for expiration, and mapped to the actions it satisfies.
Evidence handling: an uploaded artifact is typed, checked for expiration, and mapped to the actions it satisfies.
Framework control tracking on the dashboard.
Framework control tracking on the dashboard.

Managing Configuration as Code

Everything an admin can build in the console, like Library Items, Blueprints, and Assignment Maps, can also be managed as code. Iru exposes the configuration in a version-controlled repository, so teams that already run infrastructure through Git can treat device management the same way: changes go in as pull requests, get reviewed by a colleague before they land, and can be rolled back to any previous state if something breaks.

This matters for two kinds of team. The first is any IT group that has been burned by an untraceable change. With configuration in a repository, every modification has an author, a timestamp and a diff, and “who changed the firewall policy” is a search rather than an investigation. The second is engineering-led organizations where IT sits alongside a platform team. They can apply the same review gates to a Blueprint change that they apply to production infrastructure, and stage a change across environments before it reaches every device.

The same versioning runs through Workforce Identity. Application configurations, authentication policies and group definitions carry a full history; admins can edit in the interface or directly in code, compare versions side by side, and promote an earlier version to current in one step. In the demo tenant, one application was on its 41st version.

Configuration as Code is optional. Teams that prefer the console lose nothing by ignoring it, and the two can be mixed. You can edit visually day to day, and reach for the repository when a change needs review or an audit trail.

6. User Experience

We found the console easy to use and well designed. The Library is straightforward to navigate, and the fleet view makes it easy to see what is being managed and drill into individual Mac and Windows devices. Blueprints and Assignment Maps take some learning, but the per-user views make the results of a configuration clear.

Auto Groups cut identity directory work by building group membership from user attributes, and manual groups can contain automatic ones.

The console opens on deployment and security dashboards. Devices, Library and Blueprints use the same approach: filter to a platform and settings that do not apply disappear. The Library includes home screen layout controls for iPhones and iPads. Mac Blueprint templates offer four hardening levels plus CIS Levels 1 and 2. In our review, building a hardened Mac baseline meant selecting the CIS Level 2 template and creating a Blueprint from it. That was a useful illustration of how much setup the templates handle.

Sign-in to the console is passwordless: a passkey held in the device’s Secure Enclave on Mac or TPM 2.0 chip on Windows, unlocked by fingerprint or face.

For automation outside the console, Iru’s MCP server exposes its API to AI assistants. From Claude Code it can create reports, add tags to devices for more granular scoping, customize deployment logic in Assignment Maps, configure Library Items, or connect to other IT tools.

Support is included with no tiers and is staffed by former IT practitioners. Iru reports average chat responses under five minutes and CSAT scores of 95%.

The home dashboard: fleet composition, Library Item statuses, and detections at a glance.
The home dashboard: fleet composition, Library Item statuses, and detections at a glance.
Iru AI offering to configure a Windows Update Library Item based on an admin's stated goals.
Iru AI offering to configure a Windows Update Library Item based on an admin’s stated goals.
Auto Groups: membership computed from user attributes, with manual nesting available.
Auto Groups: membership computed from user attributes, with manual nesting available.
The Iru MCP connector driving the tenant from Claude Code: a device inventory pulled via the API.
The Iru MCP connector driving the tenant from Claude Code: a device inventory pulled via the API.

7. Pricing

Pricing is quote-based and scales by the products you pick plus user and device counts, on an annual commitment billed annually.

Iru starts at a 50-license minimum and goes up in blocks of 25. One person’s Mac, iPhone and iPad count as three devices for endpoint products, and one user for identity. Compliance costs under $15,000 a year, with startup discounts available. Endpoint, identity and compliance can each be bought on their own or bundled.

Support is included for all three; onboarding and migration are included for the endpoint products. A 14-day trial covers Workforce Identity, Endpoint Management, Vulnerability Management and EDR; Compliance Automation is demo-only.

8. Strengths and Cautions

Strengths

  • The agent checks configuration every 15 minutes, and continuous enforcement reinstalls required apps if users remove them.
  • Auto Apps handles patching for supported software, including applications the admin never deployed, with Mac privacy permissions pre-packaged.
  • Assignment Maps target deployments using the groups in your identity provider or device attributes, and a per-user view shows why a device is or is not getting something.
  • One agent covers management, EDR and vulnerability response on Mac and Windows; adding EDR is one Library Item.
  • Support is included and is fully staffed by former IT practitioners.
  • Identity configuration is versioned with one-click rollback, and authentication policies check device posture from Iru Access at every sign-in.
  • Compliance drafts controls for your organization, tracks evidence between audits, and includes unlimited frameworks in one price.

Cautions

  • Windows management has fewer options than Mac management. Windows behavioral EDR is scheduled for early 2027 and is not available today.
  • Android covers the COPE model only; BYOD work profiles, fully managed and dedicated devices remain on the roadmap.
  • Cloud-only: organizations requiring on-premises management are out of scope.
  • Compliance has no vendor risk management, supplier assessment or risk scoring.

9. Who It’s For

Expert Insights recommends Iru for organizations with mixed fleets where Macs make up the majority, or where IT is willing to trade deeper control for efficiency and leverage. The practical benefit is less routine work: the agent enforces device settings, Auto Apps keeps supported applications patched, and compliance automation collects evidence from device and identity data.

Iru’s own customer base is still mostly Mac and iOS fleets given its seven-year history as Kandji. Windows management is newer and still has gaps against platforms that specialize in Windows.

Each of the three products can be bought on its own, and device management is a strong product in its own right. We favor the combined platform when device management, identity and compliance are all in scope. Device state feeds sign-in decisions, identity groups drive what each device receives, and both feed compliance evidence. That connection reduces the manual work of maintaining separate products.

It is a weak fit if your use cases for Windows fall outside the scope of knowledge workers using a computer as their primary workstation. For example, managing Windows 10, Windows Server, ephemeral virtual desktops, or a shared computer with multiple users are not supported.

IT Management Resources

Further reading on it management from Expert Insights — buyers' guides, comparison articles, and platform-specific shortlists.

Written By Written By
Craig MacAlpine CEO and Founder

Craig MacAlpine is CEO and Founder of Expert Insights. Before founding Expert Insights in August 2018, Craig spent 10 years as CEO of EPA Cloud, an email security provider that rebranded as VIPRE Email Security following its acquisition by Ziff Davis, formerly J2Global (NASDAQ: ZD) in 2013.

Craig is a passionate security innovator with over 20 years of experience helping organizations to stay secure with cutting-edge information security and cybersecurity solutions.

Using his extensive experience in the email security industry, he founded Expert Insights with the singular goal of helping IT professionals and CISOs to cut through the noise and find the right cybersecurity solutions they need to protect their organizations.

Tested by Tested by
Craig MacAlpine CEO and Founder

Craig MacAlpine is CEO and Founder of Expert Insights. Before founding Expert Insights in August 2018, Craig spent 10 years as CEO of EPA Cloud, an email security provider that rebranded as VIPRE Email Security following its acquisition by Ziff Davis, formerly J2Global (NASDAQ: ZD) in 2013.

Craig is a passionate security innovator with over 20 years of experience helping organizations to stay secure with cutting-edge information security and cybersecurity solutions.

Using his extensive experience in the email security industry, he founded Expert Insights with the singular goal of helping IT professionals and CISOs to cut through the noise and find the right cybersecurity solutions they need to protect their organizations.