Device Management & MDM Operations3 min readUpdated September 2026

Kandji vs Rippling IT for a Law Firm's Privileged Files

Encryption and access control matter more at a law firm because a leaked privileged document can waive the protection it was entitled to. Kandji suits a mostly Mac firm with a stable roster, while Rippling suits one with conflicts-driven staffing changes and contract attorneys. Both lock down the laptop, but neither enforces an ethical wall alone.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Why privilege raises the stakes on a lost laptop

An unencrypted laptop lost in a cab is a bad day for most businesses. For a law firm, it's a potential breach of the duty of confidentiality owed to every client whose files were on that machine, attorney work product included. Full-disk encryption isn't a nice-to-have here, it's close to a baseline professional obligation, and it should be enforced by policy rather than left to whether an individual attorney remembered to turn it on when the laptop was issued. Both Kandji and Rippling can enforce that baseline; the difference is how much effort it takes to prove it's actually in place across every partner, associate, and paralegal laptop in the firm, including the ones nobody thinks to double-check because that person has been at the firm for years.

Kandji's case for a firm that's mostly on Macs

Many boutique and mid-size firms run an almost entirely Apple fleet, and Kandji's pre-built compliance baselines make it straightforward to demonstrate, not just assert, that encryption, screen lock, and patch levels meet a defensible standard across every attorney's laptop. Its zero-touch enrollment also matters for a firm bringing on lateral hires or contract attorneys mid-case, since a new laptop can be ready and compliant before it's ever handed over, rather than configured under time pressure while a matter is already active.

Rippling's case for firms juggling conflicts and staffing changes

Law firms deal with conflicts checks and staffing changes that other industries don't: an attorney might be walled off from a matter mid-case, or a paralegal reassigned when a conflict surfaces. Rippling ties device and access changes to the same employment and assignment record the firm already uses for staffing, so when someone's role on a matter changes, the access tied to their laptop can be updated from the same place. For a firm that handles ethical walls formally, that single point of update reduces the risk of a stale credential surviving a reassignment.

What device policy can't do for privilege on its own

Encryption and access control protect the laptop; they don't enforce an ethical wall by themselves, and they don't stop an associate from accidentally attaching the wrong client's document to an email. Those failures need their own controls, matter-based folder permissions, a document management system with real access logging, and training that treats a conflicts slip as seriously as the firm's malpractice policy implies it should be. Treat the MDM decision as the floor for device security, not the ceiling for protecting privilege, and budget separately for the document-level controls that actually enforce a wall between matters.

A mistake that surfaces during a lateral hire, not before

The gap most firms find late is a departed attorney's laptop that was returned but never actually wiped, or a departed paralegal's credentials that technically still work months after they left. This tends to surface during a conflicts check for a new lateral hire, when someone realizes the departure checklist from a year ago was never fully closed out. Building the wipe and access revocation into the same process as the employment change, rather than a separate IT task someone has to remember, closes that gap before it becomes a real problem. Smaller firms without a dedicated IT function are the most exposed here, since the task tends to fall to whoever happens to notice, which means it sometimes falls to no one at all.

Check these gaps before a lateral hire or a conflicts check exposes them:

  • Confirm that a departed attorney's returned laptop was actually wiped, not just collected.
  • Revoke a departed paralegal's credentials the same day, so they do not still work months after the person left.
  • Verify full-disk encryption, screen lock, and patch levels across every attorney's laptop before a loss occurs.
  • Add matter-based folder permissions and a document management system, since device policy does not enforce an ethical wall on its own.
  • Review device settings against the firm's own ethics and client-confidentiality obligations.

Weighing the two for your firm's shape

A firm with a small, stable roster of attorneys and a mostly Mac fleet can build a demonstrable baseline quickly through Kandji, though it should confirm the settings meet its own ethics and client-confidentiality obligations. A firm with more staffing movement, contract attorneys, or formal ethical walls that change through the life of a matter gets more value from keeping device access tied to the same record that tracks those staffing changes. Either way, the platform decision should sit inside a broader confidentiality and conflicts policy, not stand in for one, and should be reviewed whenever the firm's staffing model changes meaningfully, such as adding a contract attorney program.

Executive Capability Standard

What Good Looks Like

Every attorney and staff laptop is encrypted and enrolled before it touches a matter, and access tied to that laptop is fully revoked the same day an ethical wall, staffing change, or departure takes effect.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Audit which laptops currently have access to which matters, and confirm encryption status directly on each one rather than assuming it from the original setup.
2. Do Manually:Walk through a departure checklist by hand for every attorney or staff member who leaves, confirming the laptop wipe and access revocation explicitly.
3. Delegate:Assign one office administrator or IT lead to own device enrollment and matter-based access changes across the firm.
4. Automate:Deploy Kandji or Rippling so enrollment, encryption, and patch deadlines apply themselves as attorneys and staff are added to the firm.
5. Buy:Pair device management with a document management system that logs matter-level access, so conflicts and ethical walls are enforced at the document level, not just the device level.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

Does disk encryption satisfy a law firm's confidentiality obligations by itself?

No. Encryption protects data on a lost or stolen device, which is an important baseline, but confidentiality and privilege obligations extend to how documents are shared, who has access to a matter, and how conflicts are managed. Device management is one layer of a much broader set of professional obligations.

Can device management enforce an ethical wall between attorneys on a matter?

Not directly. An MDM manages the laptop's security settings, not which documents a specific person can open within a document management system or shared drive. Ethical walls need to be enforced at the document and permissions level, with the device policy providing the underlying security baseline.

How should a firm handle a departing attorney's laptop and credentials?

Wipe the device and revoke all access the same day the departure is effective, and confirm it explicitly rather than assuming it happened. Building this into the same workflow as the employment change, rather than a separate manual step, is the most reliable way to avoid a credential quietly surviving past someone's last day.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides