Device Management & MDM Operations3 min readUpdated September 2026

Kandji vs Rippling IT for a Firm That Sells IT to Others

For an IT consulting firm, Kandji suits a stable, mostly Mac bench, while Rippling suits a bench that shifts weekly or runs mixed operating systems. Either way, every consultant's laptop typically holds VPN access into several client networks at once, so the firm has to practice the hygiene it sells.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

A consultant's laptop is a door into several networks at once

Where a typical office worker's laptop is a risk to one company, a consultant's is a risk to every client whose network they've been granted remote access into that week. A single compromised machine can become a path into several client environments simultaneously, which is the scenario every managed services firm warns its own clients about. Whichever platform you choose, the bar for encryption, patch currency, and screen lock on consultant laptops should be the highest one in the building, not an afterthought handled the same way as the front-desk computer.

Kandji's case: proving the discipline you sell

If your consultants are mostly on Macs, Kandji's pre-built compliance baselines let you demonstrate, not just claim, that every consulting laptop meets the standard you'd insist a client meet. Its patch enforcement and audit-ready reporting are a reasonable answer the next time a prospective client asks how your own firm handles the risk you're being hired to manage for them. That kind of internal proof point carries real weight in a services sale where trust is the product.

Rippling's case: one record for a fast-moving bench

Consulting firms often staff engagements off a bench that shifts by the week, moving consultants between clients as demand changes. Rippling ties device access to the same HR record used for staffing and payroll, so when a consultant rolls off an engagement, their access to that client's VPN and systems can be revoked from the same place their assignment change is recorded. For a firm with a lot of engagement churn, that single point of update is worth more than it looks on a feature list.

The mixed-OS reality most consultancies actually have

IT consultants frequently carry a Windows laptop specifically because a client's environment requires it, even if their own preferred machine is a Mac. Kandji can't touch that Windows laptop at all, since it only manages Apple hardware. Rippling manages both from one console, which for a firm that genuinely runs a mixed fleet removes the need to run two separate systems just to cover two operating systems.

What this decision doesn't replace

Neither tool substitutes for a documented client offboarding checklist: revoking VPN credentials, rotating any shared client passwords, and confirming access removal with the client directly. A managed services firm that sells process discipline to its own clients should hold itself to the same standard on its own consultants' machines, in writing, reviewed on a schedule rather than assumed to be handled correctly by default.

Add these steps to your client offboarding checklist and your own audit:

  • Revoke the consultant's VPN credentials into each client network as soon as an engagement ends.
  • Rotate any shared client passwords the consultant could see, and confirm access removal with the client directly.
  • Audit your own bench first: list unencrypted laptops, machines behind on patches, and former consultants who still hold valid VPN credentials.
  • Check whether any consultants carry Windows laptops, since Kandji manages only Apple hardware while Rippling manages both from one console.
  • Hold the firm to the same process discipline it sells to clients, and document it.

A credibility test worth running on yourself

Before recommending a device policy to a client, run the same audit against your own consulting bench: which laptops are unencrypted, which are behind on patches, and which former consultants still technically have valid VPN credentials to a network they haven't touched in months. Most firms that do this exercise honestly find at least one gap they wouldn't accept from a client. Fixing it before a client or a prospect asks is cheaper than explaining it after they find it themselves.

Choosing based on how your bench actually operates

A firm with a stable, mostly-Mac consulting staff and a slow rate of engagement turnover gets more out of Kandji's deeper Apple-specific controls and faster initial setup. A firm that staffs and re-staffs engagements weekly, runs a genuinely mixed OS fleet, and already tracks headcount in Rippling gets more out of keeping device access tied to that same staffing record. Look at how often your bench actually turns over before picking a platform based on features alone, and weight that turnover rate more heavily than any single item on either vendor's spec sheet, since it predicts your real support burden better than any listed feature does. A firm with a stable bench can afford to optimize for depth; a firm that reshuffles staffing constantly should optimize for how fast access changes propagate across the whole bench instead.

Executive Capability Standard

What Good Looks Like

Every consultant's laptop, regardless of operating system, is encrypted, current on patches, and enrolled before it's issued for a client engagement, and access is revoked the same day that engagement ends.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Inventory which consultants hold active remote access to which client networks, and confirm each laptop's encryption and patch status directly rather than assuming it.
2. Do Manually:Check encryption and update settings by hand at the start of each new client engagement, and again when the engagement closes.
3. Delegate:Assign one internal IT lead to own device enrollment and client-access offboarding for the whole consulting bench.
4. Automate:Deploy Kandji or Rippling so enrollment, encryption, and patch deadlines apply themselves as consultants are staffed onto new engagements.
5. Buy:Pair device management with a documented, auditable offboarding process for VPN and client-system access, reviewed on the same schedule as your device compliance reports.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

Why does consultant laptop security matter more here than at a typical company?

A consultant's laptop often carries active remote access into multiple client networks at once, so a single compromised machine can expose several clients simultaneously. Managed services and IT consulting firms are also the ones advising clients on this exact risk, which makes their own lapses more visible and more costly to trust.

Does either platform revoke a consultant's VPN access to a client network automatically?

No. Device management handles the laptop itself, encryption, patching, and enrollment, but VPN and client-system access typically lives in separate systems that need their own offboarding step. Treat the device wipe as one part of a broader offboarding checklist, not the whole thing.

Is Kandji or Rippling better for a firm with mostly Windows consultants?

Kandji only manages Apple hardware, so a Windows-heavy consultant fleet rules it out entirely. Rippling manages both Windows and Mac from one console, which fits a firm running a genuinely mixed fleet better, even though its Apple-specific controls are lighter than a dedicated Mac MDM.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides