Strengthen your Mac security while boosting productivity
See how Kandji brings together everything your team needs to empower secure and productive work on Mac.
Start Free Trial
Trusted by teams at
The most-loved Mac device management for fast-growing companies
Kandji is award-winning software for innovative leaders who run on Apple.
Manage and secure Mac the modern way
Deploy and manage with zero touch
Set up work-ready Mac computers remotely with Device Management. Kandji automates tedious tasks like initial configuration, software updates, and FileVault key rotation.
Learn More about Device Management
Protect your team from threats and malware
Protect your Mac computers from a broad range of attacks with Endpoint Detection & Response that stops threats in real time.
Learn More about Endpoint Detection Response
Discover vulnerabilities and lower your risk
Know your risk exposure from all vulnerable software on Mac with Vulnerability Management. Detect vulnerabilities instantly and resolve them with automated patching.
Learn More about Vulnerability Management

“When I did our proof of concept, I got 90% of our required configurations done in 3 hours. I even told my boss, ‘Hey, I’m already done, can you believe it?’”
Robby Siu
Senior Manager, Information Technology
Automations put time back in your day
Put app updates on autopilot with Auto Apps
Keep users running the right app versions with zero manual intervention. Auto Apps handles regular updates end-to-end without interrupting users' work.

Automate macOS updates with Managed OS
Eliminate manual macOS update management. Kandji Managed OS automates the entire update cycle while respecting user workflows.

Clear configuration workflows with Assignment Maps
Visualize and control exactly what's deployed to each device. Eliminate configuration conflicts and ambiguity with clear logic on an infinite canvas.

Save time with the Kandji Agent
A single agent for EDR, MDM, and Vulnerability Management enables instant deployment, while autonomously keeping devices in your desired state.

Secure devices with one click templates
Meet security benchmarks and compliance mandates by using Blueprint templates with dozens of security controls built in. Create a secure baseline in just one click.

Unparalleled user experiences
Better employee onboarding with Liftoff
Go beyond zero touch deployment. Guide users through device setup with a branded onboarding experience, creating the perfect first day at work.

Deliver apps and more via Self Service
Empower users to solve their own IT needs with a branded self-service portal. Provide access to approved apps and resources while reducing support workload.

Update software without disrupting work
The Kandji Agent alerts Mac users days before update enforcement, with timely reminders that prevent work disruptions and maintain productivity.

Visibility into every device, vulnerability, and threat
Get answers to your questions with Kai
Get insightful answers about the state of your Apple devices at work. Harness AI to understand your fleet with complete data privacy.

View your vulnerabilities
The Vulnerabilities view shows you the risks affecting your security posture, and helps you to prioritize your remediation efforts at a glance.

See every threat
See all threat events along with the real-time response by the Kandji Agent to contain it. Dig into the important details to investigate an event and its impact.

The Kandji difference
Lowest cost of ownership
Massive reductions in device administration hours result in substantial cost savings.
Liberated IT teams
Free your security and IT teams from mundane management tasks and unleash innovative potential.
Happier employees
Elevated IT interactions result in happier users and increased CSAT scores from internal customers.
Frequently asked questions
Get answers to commonly asked questions
Kandji’s device management, malware protection, and vulnerability management cover the full scope of endpoint security which compliance programs require. Kandji makes it easy to apply the right security configurations to devices via templates, and consistently enforces those configurations to ensure that devices stay compliant.
Kandji uses Apple's Declarative Device Management framework to efficiently enforce macOS software updates. We prioritize the end-user experience by maintaining native update prompts that notify users well in advance, allowing them to install updates proactively before enforcement deadlines.
For Auto Apps—our collection of over 200 popular applications—admins can configure deployment preferences and establish automated update enforcement. Kandji will intelligently handle the entire update process—from delivering user-friendly prompts and performing silent background updates when applications aren't in use, to installing critical updates by the enforcement deadlines. This automation ensures your Mac fleet maintains consistent software versions without burdening your IT team with manual patch management.
Admins can lock down external storage access on Mac with encryption and access permission controls for USB drives, DMGs, SD cards, and server volumes.
Kandji enhances IT teams' remote support capabilities by providing detailed device data and a Device Lookup tool. This tool allows tracking of a device's assignment path, revealing deployed configurations and the rationale behind specific app or setting applications. Additionally, Kandji supports deployment of remote access tools like TeamViewer, AnyDesk, and Splashtop Business, enabling secure, unattended remote device management.
Mac computers can be enrolled in Kandji through several methods. Each method applies pre-configured settings and policies immediately upon enrollment to ensure devices are secure and compliant from the start.
- Automated Device Enrollment (ADE):
The most secure and seamless option, ADE (formerly DEP) allows devices purchased through Apple or an authorized reseller to automatically enroll in Kandji during setup, without admin intervention. This is full zero touch deployment. - Enrollment via URL:
For devices not eligible for ADE, Kandji provides a secure enrollment link that can be used to manually enroll Macs. Admins can distribute this link to users as needed. - Kandji Migration Agent:
If you're moving from another MDM, the Kandji Migration Agent can be deployed using your existing MDM to automate the transition. It minimizes user interaction and streamlines the re-enrollment process.
IT teams can deploy dozens of security controls like FileVault for disk encryption and external storage restrictions and encryption requirements. Endpoint Detection & Response (EDR) detects and mitigates malware and malicious behavior that could otherwise lead to data loss. Customers can also use identity provider integrations to restrict sensitive data access to only fully managed and secured devices.
Purchasing Kandji MDM includes access to the Kandji Migration Agent, our proprietary tool designed specifically to streamline MDM transitions on Mac. This agent deploys through your current MDM platform, requiring minimal end-user interaction to move to Kandji—just a few clicks to complete. Our team tailors the migration process to your organization's specific variables and provides dedicated support via chat and email throughout the transition. Depending on your environment and objectives, Kandji can be fully deployed across your entire fleet in as little as two weeks.