Softwr

Cybersecurity · head to head

Jamf Pro vs Semperis

Jamf Pro logo

Jamf Pro

Cybersecurity

Apple-only device management for Mac, iPhone, iPad and Apple TV, licensed per device by a public US vendor.

From
On request
Rated
-
Semperis logo

Semperis

Cybersecurity

Identity threat detection and Active Directory forest recovery for AD, Entra ID and Okta, from a privately held US vendor.

From
On request
Rated
-

The short version

  • Each has a real cost: Jamf Pro it manages Apple hardware only, so any organisation with Windows or Android devices runs a second management platform and produces two sets of compliance evidence, and the two inventories disagree with each other more often than either vendor's documentation suggests.; Semperis scope is limited to Active Directory, Entra ID and Okta, so an organisation whose critical identity lives elsewhere gets little from it, and the recovery value declines in direct proportion to how much has already moved off on-premises AD.
  • They diverge on capability: Jamf Pro covers Automated Device Enrolment, Semperis covers Active Directory Forest Recovery.
  • Prices and features above were last checked on 30 August 2026.

Where they differ

Only the attributes on which Jamf Pro and Semperis actually diverge.

Attributes where Jamf Pro and Semperis differ
AttributeJamf ProSemperis

Identical on both: starting price (On request), pricing model (quote), free tier (No), platforms (Web), user rating (Not yet rated), category (Cybersecurity).

What each one covers

Drawn from each product's published feature list. An absence here means we hold no record of it - not that the product lacks it.

Only in Jamf Pro

  • Automated Device Enrolment
  • Configuration profiles
  • Policies and scripts
  • Smart groups
  • Self Service
  • Patch management
  • Extension attributes
  • Same-day OS support

Only in Semperis

  • Active Directory Forest Recovery
  • Malware-free restore
  • Replication-stream monitoring
  • Automated rollback
  • Attack indicator scoring
  • Entra ID and Okta coverage
  • Purple Knight
  • Forest Druid

What people use each for

The jobs each tool is most often brought in to do.

Jamf Pro

  • An Apple-heavy workforce where devices ship directly to users and must configure themselves on first boot with no IT touchnot Semperis
  • Education deployments managing shared iPads across classes with per-user app assignmentnot Semperis
  • Developer organisations where engineers have administrator rights on their own Macs and management has to be achieved by policy and script rather than lockdownnot Semperis
  • Organisations needing compliance evidence for Apple devices that a general-purpose endpoint manager cannot produce at the required depthnot Semperis

Semperis

  • An organisation that cannot answer an auditor or insurer asking how long it would take to rebuild Active Directory after a destructive attacknot Jamf Pro
  • Post-incident recovery where domain controllers are compromised and restoring from system-state backup would reintroduce the attacker's footholdnot Jamf Pro
  • Continuous detection of privileged group changes and directory-level tampering that domain controller security logs missnot Jamf Pro
  • Hybrid estates where AD, Entra ID and Okta all matter and no single tool currently shows changes across the threenot Jamf Pro

Where each one falls short

Documented limitations, not opinions. Every one is a constraint you would hit in normal use.

Jamf Pro

  • It manages Apple hardware only, so any organisation with Windows or Android devices runs a second management platform and produces two sets of compliance evidence, and the two inventories disagree with each other more often than either vendor's documentation suggests.
  • Licensing is per device per year with different rates for computers and mobile devices, so spare and shared hardware sitting in a cupboard continues to consume licences until somebody actively removes it from inventory, which is nobody's job by default.
  • Apple's frameworks set the ceiling: if Apple does not expose a setting through MDM or declarative device management, Jamf cannot manage it either, so requests that are a single Group Policy object on Windows are answered with a scripted workaround or with nothing.
  • Zero-touch deployment depends on devices being registered in Apple Business Manager, which generally means buying through Apple or an authorised reseller, so machines bought retail or inherited through an acquisition cannot be supervised without wiping and re-enrolling them.
  • Getting value from it requires an Apple platform specialist who can write shell scripts, read configuration profiles and design smart group logic, and a generalist team without that skill uses a fraction of the product while paying the full per-device rate.

Semperis

  • Scope is limited to Active Directory, Entra ID and Okta, so an organisation whose critical identity lives elsewhere gets little from it, and the recovery value declines in direct proportion to how much has already moved off on-premises AD.
  • The licence buys tooling, not a proven runbook: forest recovery is only worth what your last rehearsal demonstrated, and a plan that has never been executed end to end in a lab is an untested assumption regardless of what was purchased.
  • It overlaps with backup and directory management products from Quest, Veeam, Commvault and others, so the buyer must argue internally why a dedicated product is needed alongside a backup contract that already claims to protect Active Directory.
  • Running Directory Services Protector well requires someone who understands AD internals, replication metadata and Tier 0 attack paths, and without that person the alerts on privileged changes are either ignored or auto-reverted in ways that break legitimate administration.
  • Licensing is driven by identity object counts, so directories carrying years of stale user accounts and service principals pay for objects that should have been deleted, and the cleanup project that would reduce the bill is the one nobody has time for.

Pricing, plan by plan

Jamf Pro

On request

No published plan breakdown. See the Jamf Pro review.

Semperis

On request

No published plan breakdown. See the Semperis review.

Which should you pick?

Choose Jamf Pro if

  • You need automated device enrolment.
  • You also want configuration profiles.

Choose Semperis if

  • You need active directory forest recovery.
  • You also want malware-free restore.

Questions people ask

Is Jamf Pro or Semperis better?
Neither clearly leads. Jamf Pro starts at On request and Semperis at On request, and user ratings are close enough to be indistinguishable. Choose on capability and platform support.
Which is cheaper, Jamf Pro or Semperis?
Jamf Pro starts at On request and Semperis at On request.
Does Jamf Pro or Semperis run on more platforms?
Both run on Web, so platform support will not decide this one for you.
What is Jamf Pro best used for?
Jamf Pro is most often used for an apple-heavy workforce where devices ship directly to users and must configure themselves on first boot with no it touch, education deployments managing shared ipads across classes with per-user app assignment, developer organisations where engineers have administrator rights on their own macs and management has to be achieved by policy and script rather than lockdown, organisations needing compliance evidence for apple devices that a general-purpose endpoint manager cannot produce at the required depth. Of those, an apple-heavy workforce where devices ship directly to users and must configure themselves on first boot with no it touch and education deployments managing shared ipads across classes with per-user app assignment are not what Semperis is typically brought in for.
What can Jamf Pro do that Semperis cannot?
Jamf Pro covers Automated Device Enrolment, Configuration profiles, Policies and scripts, Smart groups. Semperis covers Active Directory Forest Recovery, Malware-free restore, Replication-stream monitoring, Automated rollback.

Answered from the vendors’ own pages

Jamf Pro: Does Jamf Pro include endpoint security?

No. Threat prevention, endpoint telemetry and compliance monitoring are Jamf Protect, a separate product and a separate licence. Jamf Connect for identity and password sync is also separate.

Semperis: Does this replace my backups?

No. It replaces the Active Directory recovery procedure specifically. You still need backups for everything else, and the point of Semperis is that a generic system-state backup of a domain controller is a poor way to recover a forest because it restores the operating system along with whatever compromised it.

Jamf Pro: Can it manage Windows or Android?

No. Jamf manages Apple platforms only. A mixed estate needs a second management platform, and that is a deliberate product decision rather than a gap they intend to close.

Semperis: Is it useful if we are cloud-only on Entra ID?

Partly. Directory Services Protector covers Entra ID and Okta for change tracking and posture, but the forest recovery product, which is the strongest reason to buy, applies to on-premises Active Directory. A genuinely cloud-only organisation should weigh it against Microsoft's own tooling.

Jamf Pro: Do I need Apple Business Manager?

For zero-touch enrolment and volume app licensing, yes. You can enrol devices manually through a user-initiated flow without it, but you lose supervision, automatic enrolment and the ability to prevent a user removing management.

Semperis: Are Purple Knight and Forest Druid really free?

Yes, both are free downloads with no licence requirement, and they are widely used by organisations that are not Semperis customers. They are also, transparently, the top of the sales funnel.

Jamf Pro: Can I host it myself?

Yes, Jamf Pro can be self-hosted, though Jamf Cloud is the default and receives new capabilities first. Self-hosting means you own the upgrade cadence, which matters because Apple's September releases set the timetable.

Semperis: How long does forest recovery actually take?

The honest answer is whatever your rehearsal took. The vendor's case is hours instead of days, and automation genuinely removes most manual steps, but the number that matters for your board is the one from a test in your own environment.

Jamf Pro: How does it compare to Microsoft Intune?

Intune manages Apple devices adequately and is often already paid for in an existing Microsoft agreement, which is the argument against Jamf. Jamf is deeper, supports new Apple releases faster, and has the local agent for scripting. Organisations with a few hundred Macs and a strong Apple culture generally choose Jamf; those with a handful of Macs in a Windows estate generally do not.

Semperis: Does it require agents on domain controllers?

It collects directory changes from the AD replication stream, which is what lets it see changes that bypass the security log. Deployment details vary by product and version, so confirm the exact architecture against your domain controller change-control rules.

Share

Related pages

Other head to heads