We performed a comparison between Microsoft Endpoint Configuration Manager and Quest KACE Systems Management based on our users’ reviews in five categories. After reading all of the collected data, you can find our conclusion below.
Comparison Results: Because users of Microsoft Endpoint do not mention a clear and proven ROI, Quest KACE Systems Management comes out on top in this comparison.
"While I don't think you can ever have full visibility and control, Intune certainly allows us to see the applications being used and tells us if things like Windows patches aren't applied to machines. It does a good job. That visibility makes life a little easier."
"Intune enables us to manage our devices from anywhere."
"The biggest thing for us is enforcing logins only from devices that are managed by Intune."
"The feature I like the most is that we can perform remote tasks. If we want to retire or wipe out personal data or corporate data from a device, we can use Microsoft Intune remotely, and with the click of a button, data is removed automatically. Nothing needs to be done from the end-user side."
"One of the biggest advantages of Microsoft Intune is that it brings the management of Windows, macOS, iOS, Android, and even Linux under a single pane of glass."
"The synchronization of Intune with other Microsoft solutions is a valuable feature."
"Intune device restriction policies enable me to enforce limitations on the device, like blocking the mobile camera or restricting the employees from using and inserting USB devices, including thumb drives and flash drives."
"It supports end-users who tend to lock their devices quite frequently. Its conditional access policy helps us keep the users logged into their devices."
"Valuable features include configurations enforcement, compliance data gathering, and deployment of a standardized OS."
"It does the job and meets our needs. With everybody working remotely these days, we are using this solution to deploy everything. The deployment of PCs is easy."
"The most valuable feature of Microsoft Endpoint Configuration Manager is the availability of being able to manage the Microsoft estate. It handles many areas, such as asset management and tracking."
"I like the data collection."
"The solution doesn't require any maintenance from our end because it is a cloud-based solution and Microsoft takes care of everything."
"I like a lot of the reporting capabilities and baseline configurations."
"I like its ease of use. It does what you need it to do, and it's a one-stop-shop for the company and for all your deployments. If you incorporate Intune into it, you can have both. You can bring your own devices and corporate devices, and everything runs out of SCCM and Intune."
"Microsoft has done a good job with authentication solutions, such as single sign-on, or open authentication."
"This solution makes it easy to control assets and upgrade all types of software."
"The information available via KACE is up to date, critical to our normal operations, and has become the go-to tool of our IT teams for extended support."
"It is excellent in terms of updating and configuring everything the way we need. For anything more complex, we do professional service engagements, and they're exceptional. For anything less complex, we just need to ask questions. Their support division is extremely good too."
"KACE has made our life much easier since we got off the Microsoft solution. The Microsoft solution was a lot harder to image over different ports and stuff. They would only have this one place where we could do all the imaging. Now, we have a whole building where we can image from. This means that we can image from our storage area, where we have a place to do our imaging. We can also image right at our desks, which is a lot easier."
"It also does patch management. At the moment, I'm rolling out a new feature update, 20.8.2, and it's a great challenge because we have to deploy it to 1,200 computers in the home office. We want to do it without interrupting production, but KACE is reliable and it's easy to adapt it to my needs for how and when to deploy the feature update."
"The most valuable feature is the ability to monitor updates—the software versions—on machines so that we can keep everything compliant."
"Pretty much all of the features are valuable. The inventory is very helpful to be able to keep track of our devices. The deployments make it easy to deploy new software packages or upgrade packages. The help desk is also a great tool for tracking problems and problem tickets."
"I like how when you click on the device, it shows you everything that has changed as well as the software versioning. I am really enjoying the inventory aspect of it."
"We haven't really gone through all the features of Intune. We are just discovering them. Every day, we see a new feature that we want to apply, but what will be great for Intune is to be able to deploy apps in a simple fashion. We should be able to easily install various apps on the Windows platform, iOS, and Android. Currently, we have to write some scripts. It's not as straightforward as we would like it to be. It should be simplified so that we can do it just with three clicks—next, next, finish—without needing to write a script."
"They should improve its compatibility with other operating systems such as iOS and Linux. It supports Linux but they still need to work on the iOS part."
"The installation could be improved to be simplified."
"Sometimes, updating a client policy is very difficult. This needs to be improved."
"The reporting needs to be a bit more interactive."
"I would like the ability to install the agent on devices from suppliers, which would enable us to implement a zero-trust strategy for guest devices."
"It needs incorporation of Knox, ZeroTouch, etc."
"No option to do end-to-en macOS management. Slow implementation of policies."
"Cloud-based improvements need to be better managed."
"There should probably be better remote support. They should also continue to improve on patch management, patching, and creating or turning products in software into deployable apps."
"Its client interface should be more accessible, and the notifications should be more customizable from the console. It should be more user friendly and have some kind of customized notifications so that we can use it on the client side. These are the reasons why we restricted its use only for the server environment and didn't use it on the client side."
"As far as load balancing across, they don't have that support yet, so that you can actually build multiple primaries and have it load balance across. They don't have any of that functionality yet. That would be a nice feature, to scale that way."
"They should improve their anti-malware policies like the SCEP policies. For instance, you can't have different policies for different servers, there is only one policy in all the servers, and everything is covered under that. For example, say you want to scan one group of servers on Saturday, and then you want to scan another group of servers on Sunday, you can't do that. You have to scan all your servers, a regular scan or a full scan, on the same day and at the same time. That's definitely one thing they need to resolve. In the next release, it would actually be nice if they included Apple products. It will also help if you can use Intune again. Their compliance reporting feature could also be better. They can maybe work a bit on that for patching now. It would be better if SCCM came with the functions of Right Click Tools built-in. If SCCM would have all those functions already built-in, we won't have to go and spend $5,000, just as an add-in from another company to get those functions."
"There is a reboot issue with the patching. Sometimes, if patching runs into any issue whatsoever, it doesn't reboot but it doesn't tell you it errored out. It just sits there and we don't find out until the next day whether it patched or not. That was a big issue for us. We're working through that. They added some stuff in there now where you can actually tell reboot is pending. But we still need some kind of notification that if something fails or is pending, we know. We shouldn't have to go in and look. They don't have anything for that right now."
"There is no asset management package included."
"Microsoft Endpoint Configuration Manager can improve by allowing us to schedule the scripts, we don't have a script scheduling option and have to do it manually."
"The problem is that it's harder to directly emulate a lot of the stuff that the group policies do, using the KACE solution. With regular group policies, you just specify the various settings you want to change on the workstations, and then you specify the workstations and—while it's kind of an ugly mess—it does it. Whereas on KACE, you really have to know what you're doing with scripting to effectively script those exact same changes."
"Imaging becomes a problem when you start to try to go beyond doing more than thirty or forty machines at a time. We initially tried to do that virtually and it just, it wouldn't work."
"There is always room for improvement. However, the system does most of what we need at this moment."
"I have complaints about smart label adaptation and because of this, I recommend a 24 to 48 hour bake-in period."
"I would sure like them to be able to copy and paste out of OneNote. That drives me nuts. You can't copy from OneNote into KACE."
"We had issues with the tool's support. We are a Dutch firm and everything has to be in Dutch. We were not able to do the alerts. You were required to tweak them a lot to get them in the language that you preferred. The solution's support depended on the person that you got online. Sometimes, the response was fast and other times you needed to wait a long time. The support also depended on the levels of support that you had requested."
"The solution needs to have the ability to push out managed feature updates from Microsoft in a more seamless way."
"The software asset management functionality is an area that needs to be improved. It could be more automated because when connections need to be made, such as when I connected Adobe and my malware removed, the process was pretty much manual."
More Microsoft Configuration Manager Pricing and Cost Advice →
More Quest KACE Systems Management Pricing and Cost Advice →
Microsoft Configuration Manager is ranked 2nd in Configuration Management with 78 reviews while Quest KACE Systems Management is ranked 9th in Configuration Management with 38 reviews. Microsoft Configuration Manager is rated 8.2, while Quest KACE Systems Management is rated 8.8. The top reviewer of Microsoft Configuration Manager writes "Affordable, easy to use, and easy to understand". On the other hand, the top reviewer of Quest KACE Systems Management writes "Easy to use, saves us time, and increases IT productivity". Microsoft Configuration Manager is most compared with Red Hat Ansible Automation Platform, ManageEngine Endpoint Central, BigFix, Tanium and ServiceNow Discovery, whereas Quest KACE Systems Management is most compared with Microsoft Windows Server Update Services, BigFix, Red Hat Ansible Automation Platform, Automox and ManageEngine Patch Manager Plus. See our Microsoft Configuration Manager vs. Quest KACE Systems Management report.
See our list of best Configuration Management vendors and best Patch Management vendors.
We monitor all Configuration Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.