Device Management & MDM Operations3 min readUpdated September 2026

Kandji vs Rippling IT for a Multi-State Tax Practice

For a corporate and multi-state tax advisory practice, Kandji suits a small, stable Mac-based team that needs a fast, demonstrable security baseline, while Rippling suits a firm with frequent staffing changes tracked through payroll. The risk sits in fewer, higher-value client relationships, and tax preparers are generally expected to keep a written data security plan.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Why concentrated corporate data changes the risk profile

A firm handling individual returns spreads risk across many smaller files; a corporate and multi-state tax practice concentrates a huge amount of one client's financial detail, across every state that client operates in, onto a smaller number of engagement files. A single compromised laptop at this kind of firm can expose far more material per incident than the same laptop would at a high-volume personal-return shop, which argues for treating every preparer's device with the same rigor regardless of how senior or client-facing that preparer is, junior staff included.

Kandji's case for a firm running mostly Macs

If your preparers and advisors work primarily on Macs, Kandji's pre-built compliance baselines and fast enrollment give you a demonstrable way to show that every laptop touching a client's multi-state filings meets a defensible standard, which matters directly when a client's own finance team asks how their data is protected before signing an engagement letter. Its zero-touch setup also helps when a new advisor joins mid-year, since a laptop can be ready and compliant before their first client call rather than sometime during their first week.

Rippling's case for firms with year-round staffing changes

Corporate and multi-state tax advisory work runs closer to a year-round practice than a seasonal one, with staffing changes happening throughout the year rather than concentrated around a single filing deadline. Rippling's tie between device access and the same employment record used for payroll means a departing advisor's laptop and access to client files can be revoked from the same place their employment ends, which matters for a firm that doesn't have the natural seasonal checkpoint a personal-return practice uses to catch up on offboarding work, since nothing else naturally prompts the review.

What travel between client sites adds to the picture

Advisors visiting a client's headquarters for planning meetings carry laptops loaded with that client's multi-state filing history outside the office more often than a typical accounting role would. Full-disk encryption matters here specifically because the device is more likely to be lost or stolen while traveling than a laptop that never leaves a single building, and the baseline standard should reflect that rather than assuming office-only usage patterns that don't match how the work actually happens.

A mistake that compounds across multiple states

The failure that's specific to multi-state work is treating client data as one undifferentiated pool rather than tracking which state-level filings a given advisor actually needs access to. An advisor who only works on one state's portion of a client's filings but has laptop access to the client's entire multi-state file set is carrying more exposure than their actual role requires. Scoping access to what each advisor genuinely needs, rather than granting broad access by default, limits how much a single compromised laptop can expose across every state a client operates in.

Weighing the two for how your practice actually runs

A firm with a small, stable advisor team on Macs and infrequent staffing changes gets a fast, demonstrable baseline from Kandji. A firm with more frequent staffing changes throughout the year, already tracked through Rippling for payroll, gets more recurring value from keeping device access tied to that same employment record automatically. Either way, loop in whoever owns your written information security plan so the platform choice actually supports it.

Building a record you can hand a client's finance team

Corporate clients evaluating a tax advisory relationship increasingly ask how the firm protects the data it will be handling, before a single filing is prepared. Keep a simple, current record of every advisor laptop's encryption and patch status, refreshed on a regular schedule, so that question has a ready answer instead of triggering a scramble. A firm that can produce this on request, rather than promising to look into it, tends to close that part of the conversation faster and with more confidence on both sides.

A simple record you can hand a client's finance team should cover the following:

  • Each advisor laptop's full-disk encryption status, since travel to client sites makes loss or theft more likely than for a desk-bound role.
  • Each laptop's current patch status, refreshed on a regular schedule so the answer is ready before a client asks.
  • Which state-level filings each advisor works on, so laptop access matches that scope instead of a client's entire multi-state file set.
  • Your written information security plan, with its contents confirmed by your own compliance advisor rather than assumed.
  • Staffing changes and the matching device changes, so a departing advisor's laptop access has a clear end point.
Executive Capability Standard

What Good Looks Like

Every advisor's laptop is encrypted and enrolled before they access a client's filings, and their access is scoped to the specific states and engagements they actually work on, revoked fully the same day their role changes.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Map which advisors currently have access to which clients' multi-state filings, and confirm whether that access is actually scoped to their real role.
2. Do Manually:Walk through access scoping by hand for each new engagement, granting only the specific state and client access an advisor's assignment requires.
3. Delegate:Assign one practice manager to own device enrollment and access scoping across every advisor and every multi-state engagement.
4. Automate:Deploy Kandji or Rippling so device enrollment, encryption, and patch deadlines apply themselves as advisors join or change roles throughout the year.
5. Buy:Pair device management with a documented written information security plan reviewed with a compliance advisor, covering data handling across every state your clients operate in.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

Are tax preparers required to have a written data security plan?

Tax preparers are generally expected under IRS guidance to maintain a written information security plan covering how client data is protected, including on devices that leave the office. The specifics of what your plan needs to cover depend on your practice, so confirm the details with your own compliance advisor rather than assuming a general answer applies.

Should access to a client's multi-state filings be limited by which state an advisor works on?

Scoping access this way limits exposure if a single laptop is compromised, since that advisor's device only carries what they actually need rather than the client's entire file set. It takes more setup discipline than granting broad access by default, but it meaningfully reduces the blast radius of any single incident.

Does Rippling's device management help with a mid-year staffing change?

Yes. Rippling ties device access to the same employment record used for payroll, so a mid-year departure or new hire triggers the device change from that record. No separate manual process is needed outside the normal seasonal cleanup a personal-return practice might rely on, which keeps year-round staffing changes from waiting on a manual step.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides