Kandji (now Iru)
Depends
Confidence: Medium
Buy if you run a large, Apple-heavy fleet with dedicated IT staff and want MDM, EDR, and vulnerability management consolidated.
Comparison
Kandji (now Iru) and NinjaOne both land on Depends.
Buy if you run a large, Apple-heavy fleet with dedicated IT staff and want MDM, EDR, and vulnerability management consolidated.
Buy if you're an MSP or IT team managing dozens to thousands of endpoints and can absorb per-device costs.
| Compare | Kandji (now Iru) | NinjaOne |
|---|---|---|
| Verdict | Depends | Depends |
| Best for | Mac-heavy fleets with dedicated IT | MSPs managing many client tenants |
| Who it's not for | Tiny teams managing a handful of Macs | Anyone managing under ~20 devices . serious overkill |
| Privacy | Sells vulnerability management, but its own agent shipped a privilege-escalation CVE in June 2026.⁸ | SOC 2 compliant per NinjaOne Trust Center; no product breach found, but researchers documented an RMM agent abuse chain. |
| Support quality | 24-hour support since 2023; complaint threads exist | No support evidence found |
| Public sentiment | Polarized: 4.7/5 on G2, but Trustpilot sits at 2.5/5 and some Reddit admins are scathing.² | Reviewers rate NinjaOne a best-in-class RMM with 98% G2 satisfaction, while Reddit MSPs gripe about price and weak reporting.14 |
| Biggest gotcha | CVE-2026-39118: macOS flaw let standard users disable Kandji MDM and CrowdStrike; verify patched agent⁹ | Cato researchers documented threat actors abusing the NinjaOne agent; enforce MFA and least privilege |