RMM keeps every device working — patched, monitored, fixed at a distance.

One agent, one console: monitor, patch, script and reach every machine on a schedule. Keeping devices working is a different job from proving them compliant — that is the UEM next door — and most of the category still carries its Windows-first heritage into macOS and mobile.

Atera bills per technician, unlimited devices. NinjaOne bills per device. At 2,000 endpoints the same job differs by multiples before a single feature is compared.

Already decided — before the demo

OS mixWindows-first heritage sets Mac and mobile depth
Remote / UEM licences you holdset the double-buy question
Technician headcountsets the per-seat bill

Still yours to weigh

Pricing modelper technician, per device, free-to-200
What's bundledpatch, backup, security, ticketing
Tenancy and scale200, 2,000 or 10,000 endpoints
If you’ve never bought one

What RMM & patch management actually is

Remote monitoring and management is an agent on every machine reporting to one console, and the console doing four things back: watching (health, disk, services, events), patching (the OS and the applications on it, on a schedule, in rings), scripting (the same fix on a thousand machines at once) and reaching in (remote control when a human has to look). It grew up in managed-service providers running other organisations’ fleets, which is why the pricing models, the multi-tenancy and the Windows-first heritage look the way they do.

Patch management on its own is the second of those four, sold as a product. In 2026 almost every RMM bundles it, and several patch-first tools have grown monitoring and remote access back in the other direction — so judge the product by what it does to your top twenty applications on every OS you run, not by the label.

The line that matters most

An RMM’s green tick means the device responded and the patch installed. A UEM’s green tick means the device is enrolled, configured, encrypted and provably so. Auditors ask for the second. Buy an RMM expecting the first to satisfy them and you will be buying a UEM afterwards — that guide is here.

RMM vs UEM, from the RMM side

Same agent count, different question. RMM answers ‘is it working?’; UEM answers ‘is it in the state we declared?’. ManageEngine Endpoint Central and NinjaOne (with its MDM add-on) straddle both; the rest are one or the other.

RMM vs patch-only tools

A patch tool detects, approves, deploys and verifies updates. An RMM does that plus monitoring, scripting, remote access and usually ticketing. Action1 started as the first and now does most of the second; buy it for patching and treat the rest as bonus.

RMM vs monitoring

Monitoring watches and alerts; it changes nothing. An RMM watches, alerts and then acts — a script, a patch, a restart, a remote session. If nobody will act on the alert, you wanted monitoring, and you wanted less of it.

Often confused withUEM & MDM — devices in a known, provable state →· Remote Access & Support — one human on one screen, and what can be proven afterwards →

The four routes of endpoint management — and which one is yours →

The narrowing instrument · the reasoning is the product

Narrow 24 products to your shortlist

Set what you know. Nothing leaves the page: a product that stops qualifying fades and carries the reason; one we cannot verify for your case carries a note and stays. Unset a chip and it returns.

The six variables that decide it:OS coveragePricing modelWhat's bundledScripting depthMulti-tenancyScale behaviour

Commercial shape

Hosting

What's bundled

OS coverage

Fleet size

Tenancy

Windows and macOS patching, remote access and scripting remove nothing here — all seven have them. Their differences in depth are in the reasoning below and in Patch, really.

Still in24/ 7
Qualys logo

per asset / year, quoted — sold on the Qualys Enterprise TruRisk Platform alongside VMDR rather than as a standalone RMM; TruRisk Eliminate adds mitigation where no patch exists

Estates where patching is driven by VULNERABILITY RISK rather than by a monthly update cycle. Qualys finds the vulnerability and fixes it from the same agent and the same console, so the prioritisation and the remediation share one risk model instead of being reconciled across two tools — which is the handover where most remediation programmes actually leak. The India platform is Pune-engineered, which matters for a residency conversation.

The catch: This is not an RMM: no PSA, no ticketing, no remote-control-led workflow, no mobile management. If you want one console for helpdesk and endpoint operations, look at NinjaOne or Atera instead. It is also quote-only and sold as part of a platform, so the sizing conversation is about the whole TruRisk entitlement rather than a per-device patch price.

Vulnerability-led remediationIndia platform (Pune)Not an RMM — no PSA
Intel page →
NinjaOne logo
$1.50–3.75

per device / month — NinjaOne publishes $3.75 at 50 or fewer endpoints down to $1.50 at 10,000 and quotes the exact rate; the patching capability within the NinjaOne platform rather than a separate purchase; approval rings and scheduled deployment across Windows, macOS and Linux plus a third-party application catalogue

Teams that want patching with real deployment discipline — approval rings so updates reach a pilot group before the fleet, scheduling that respects maintenance windows, and reporting an auditor will accept. Cross-platform including Linux, with a third-party application catalogue, which is the part most native tooling handles badly.

The catch: It is a capability of the NinjaOne platform, not a standalone product, so you are really evaluating NinjaOne — see the NinjaOne RMM entry for the commercial shape, including the published per-device band and the quote that sets the exact rate. If you want patching WITHOUT an RMM platform underneath it, Action1 or Qualys are the cleaner comparisons.

Approval ringsWindows / macOS / LinuxPart of the platform, not standalone
Intel page →
SuperOps logo
$1.50≈ ₹125

per endpoint / month at the 100-endpoint minimum on the internal-IT plans, PUBLISHED — patching is included in both rather than gated behind a tier, and the same rate carries the RMM and the service desk; MSPs buy per technician instead (Standard RMM $99, Super $159 a month on annual billing, 150 endpoints each)

Mixed Windows, macOS and Linux estates that want one patch policy across all three rather than a side process for whichever platform the tool half-covers — with maintenance windows per client, failed-patch visibility, and failures that raise tickets because the service desk is in the same product.

The catch: The third-party application catalogue is thinner than NinjaOne's, which has the broadest in the category. Build your top-20 application list and check it during the trial — that single test decides this purchase, and a miss means manual patching forever. The IT plans' 100-endpoint minimum is hard, and hosting is the US or Europe only — no India region.

Windows / macOS / LinuxPUBLISHED pricingIncluded, not a tierThinner third-party catalogue
Intel page →
Action1 logo

per endpoint / month above the free tier — the same entitlement as the rest of Action1, so deployment is not a separate line item. Deploy, install, update AND uninstall applications, including custom packages

Teams whose real problem is not patching what is installed but controlling WHAT is installed — pushing a new application to a fleet, updating one that is not in any catalogue, or removing software that should not be there. The uninstall half matters more than vendors usually admit: unremoved software is unpatched attack surface that nobody is tracking.

The catch: Windows-first — Linux is not a documented patching target here, so mixed estates need something else alongside. And it is one capability of the Action1 platform rather than a standalone purchase; the free-to-200-endpoints tier and per-endpoint pricing above it are Action1’s, not this feature’s.

First 200 endpoints freeFree to 200 endpointsDeploy AND uninstallWindows-first
Intel page →
Action1 logo

per endpoint / month above the free tier. Continuously discovers vulnerabilities and remediates them from the same agent — find and fix in one tool rather than two

Organisations under CERT-In or sectoral pressure to demonstrate that vulnerabilities are not merely FOUND but FIXED, within a defined window. Most estates run a scanner and a separate deployment tool, and the gap between them is where remediation programmes fail — findings get exported, assigned, and quietly age. One tool that does both removes the handover entirely, and the free tier means you can prove it works before spending anything.

The catch: Windows-first, so Linux and macOS-heavy estates need something alongside it. Its vulnerability detection is not as deep as a dedicated scanner — if you need the breadth of Qualys or Tenable for the FINDING half, use Action1 for the fixing and accept two tools. And the free tier, while genuinely generous, is a starting point rather than a permanent answer at scale.

First 200 endpoints freeFind AND fix in one toolFree to 200 endpointsNot a deep scanner
Intel page →
GoTo / LogMeIn logo
LogMeIn CentralGoTo / LogMeIn
Quote

per device, quoted by edition — the veteran cloud endpoint-management platform: remote access at fleet scale plus monitoring, Windows and third-party patch management, and LogMeIn Antivirus as a paid module

Teams already standardised on LogMeIn for remote access who want monitoring and patching in the same console rather than adding a second platform. The remote-access heritage is genuine depth rather than a bolted-on afterthought, and for a helpdesk-led operation that is the workflow people actually live in.

The catch: Remote-access-first rather than patch-first: the patching is competent for Windows and third-party applications and it is not the reason anyone buys this. No documented Linux patching, no mobile management, no PSA. If patching is your primary requirement rather than remote access, Action1, NinjaOne or ManageEngine are stronger answers and cheaper ones.

Remote-access heritageWindows + third-partyPatch is not the headline
Intel page →
NinjaOne logo
NinjaOne RMMNinjaOne
$1.50–3.75

per device/mo — NinjaOne’s published band: $3.75 at 50 or fewer endpoints, falling to $1.50 at 10,000 (USD; varies by region and products bought); exact rate by quote

Internal IT and MSPs wanting the broadest Windows / macOS / Linux RMM — patching, scripting, remote access — with MDM, backup and endpoint security as add-ons in the same console.

The catch: Only a price band is published and the exact rate is quoted; small fleets sit at the top of the band, per-device billing climbs linearly with the fleet, and MDM, backup and endpoint security are each a separate paid add-on.

Per deviceMulti-tenantLinux patchingAdd-on MDM / backup / EDR
Intel page →
Atera logo
$149≈ ₹12,367

per technician/mo, unlimited devices (Professional, annual; Expert $189, Master $219)

Small IT teams running many devices: headcount, not fleet size, sets the bill — RMM, patching, remote access and a PSA in one.

The catch: Every login is a paid seat (no read-only tier); Network Discovery adds $29 per technician (AI Copilot is now in every plan); third-party patching rides on WinGet / Chocolatey / Homebrew / APT rather than a curated catalog.

Per technicianPSA includedLinux patchingPackage-manager patching
Intel page →
SuperOps logo
SuperOps RMMSuperOps
$1.50≈ ₹125

per endpoint/mo at the 100-endpoint minimum — PUBLISHED; $1.40 (101–500), $1.30 (501–1,000), $1.20 (1,000+). Prime Plus $2.50 early-bird (list $3.00) → $2.00. That is the internal-IT price book; MSPs pay per technician — Standard RMM $99, Pro $129, Super $159 a month on annual billing, 150 endpoints per licence

Small-to-mid MSPs (roughly 1–25 technicians) and internal IT of similar scale who want a price they can read off a public page and the service desk in the box rather than as a second contract — India-built in Chennai, so support hours match the Indian working day.

The catch: The third-party application catalog is thinner than NinjaOne's — build your top-20 application list and check it in the trial, because that single test decides this purchase. The IT plans' 100-endpoint minimum is hard, hosting is the US or Europe with no India region and no self-hosted option, and no analyst quadrant placement is possible for MSP-centric RMM vendors.

PUBLISHED pricingPer endpointPSA includedLinux patchingIndia-built
Intel page →
N-able logo
Quote

per device / month, quote-only — third parties report ~$1.50–3.50 by volume, term and bundle, with an Essentials edition from ~$1.05; those are REPORTED figures, not N-able's own

MSPs running many client estates that must be genuinely separated — architectural multi-tenancy with per-client policy and role-based access, plus SNMP network-device monitoring that can retire a second monitoring system, across Windows, macOS, Linux and cloud.

The catch: The heavyweight of N-able's TWO platforms, and choosing wrongly is the expensive mistake here: it takes weeks rather than days to stand up because the policy is designed, not switched on. If you manage one estate, N-sight is the right answer. Quote-only with no published rate card, and the Bengaluru GCC does not answer data residency.

Real multi-tenancySNMP network devicesWeeks to stand upQuote-only
Intel page →
N-able logo
Quote

per device / month, quote-only — reported below N-central; both platforms share the same patch engine, so Windows, macOS and Linux coverage is identical

Support-led shops and lean IT teams with one estate (or a handful they need not wall off) who want monitoring, cross-OS patching, ticketing and a genuinely strong attended and unattended remote-support workflow — working in days rather than weeks.

The catch: Lighter multi-tenancy than N-central, and SNMP network-device monitoring is not a strength — if either is load-bearing, buy N-central and accept the longer implementation. Automation is shallower than N-central's policy engine. Quote-only, like the rest of the portfolio.

Days to stand upStrong remote supportLighter tenancyQuote-only
Intel page →
Action1 logo
Action1Action1
Quote

per endpoint/mo beyond 200 (Growth, annual) + a support subscription

Patch-first teams: Windows / macOS / Linux patching, software deployment and vulnerability remediation, free until the 201st endpoint.

The catch: Patch-and-deploy first, RMM second — monitoring and alerting are lighter than NinjaOne or Atera, there is no PSA, and the macOS third-party catalog (~30 apps) is far narrower than Windows.

Free for the first 200 endpoints — no feature limits (verified Aug 2026)Free to 200Per endpointMulti-tenantLinux patching
Intel page →
Action1 logo

per endpoint / month above the free tier — the same entitlement as the rest of Action1, so the remote-management features are not a separate line item. Real-time monitoring and alerts, browser-based remote desktop, remote PowerShell/Bash scripting and multi-tenant views

Lean IT teams and MSPs that want remote control and endpoint visibility on the SAME agent that already patches the fleet — one tool, one agent, no second console to stand up. The case is efficiency for endpoint-centric teams rather than breadth.

The catch: These are the remote ESSENTIALS on a patch-first platform, NOT a full RMM+PSA — Action1’s own positioning. No ticketing, no PSA or billing, no SNMP or network-device monitoring and no mobile admin app. NinjaOne, Atera and ManageEngine Endpoint Central do materially more here, and TechBag sells all three.

First 200 endpoints freeSame agent as patchingNo ticketing or PSANo SNMP monitoringFree to 200 endpoints
Intel page →
ManageEngine logo
$1.33–2.83≈ ₹110

per endpoint/mo equivalent — Professional → Security, per 50 endpoints a year, on-prem

Teams wanting RMM-grade patching and software deployment inside a full UEM — on-prem, or India-hosted.

The catch: Windows-first console heritage shows; each edition includes one technician (more are paid), and multi-tenancy is the separate Endpoint Central MSP edition, not a switch.

Free edition — up to 25 endpoints (verified)India-builtOn-prem / India DCUEM + RMM in oneFree to 25
Intel page →
Splashtop logo
Splashtop AEMSplashtop
Under $1≈ ₹83

per endpoint/mo (vendor-stated ceiling); 100-endpoint minimum; one technician licence per 10 endpoints

Teams already on Splashtop remote access adding real-time OS and third-party patching, CVE visibility and scripting — same agent, no second tool.

The catch: Patches Windows and macOS only (Linux is remote-control only), 100-endpoint minimum, and monitoring / alerting depth sits below a full RMM.

Add-on to SplashtopPer endpointWin / mac patching only
Intel page →
GoTo / LogMeIn logo
LogMeIn ResolveGoTo / LogMeIn
Per endpoint

per endpoint/mo, billed annually — Starter · Advanced · Complete; 25-endpoint minimum, unlimited technician users; patching starts at Advanced (Windows), application patching and MDM at Complete; GoTo draws the dollar figures in the browser, so TechBag confirms today’s per-endpoint price

Helpdesk-first teams wanting remote support, ticketing, patching and a built-in MDM in one light console.

The catch: Windows and macOS patching only; monitoring and scripting are lighter than NinjaOne or Atera, and patching is not in the entry Starter plan — Windows patching starts at Advanced and application patching at Complete; the product was renamed from GoTo Resolve.

Also Remote Support25-endpoint minimumHelpdesk includedWin / mac patching only
Intel page →
TeamViewer logo

per endpoint, annual (TeamViewer ONE Standard / Advanced / Enterprise; patching from Advanced)

TeamViewer estates adding monitoring, asset and patch management to the remote-access agent already on every machine.

The catch: Quote-only with a 100-endpoint minimum; patching is Windows / macOS only and starts at the Advanced tier; remote-access-first, so monitoring and scripting are add-on-grade beside a dedicated RMM.

Add-on to TeamViewerPer endpointWin / mac patching onlyBackup add-on
Intel page →
ConnectWise logo
ConnectWise RMMConnectWise
Quote

quote-only in three packages — Essentials, Pro and Premium (Premium adds unlimited ScreenConnect agents, ScreenConnect Remote Support and Microsoft 365 backup); ConnectWise publishes no price

MSPs that want a cloud-native RMM with NOC-tested Windows updates, third-party patching and ScreenConnect built in, on the same ConnectWise Platform as its PSA and SIEM.

The catch: Quote-only, cloud-only, and ConnectWise documents no India storage region; Linux patching is not documented (Linux is monitored), and it shares 2025’s code-signing certificate rotation with ScreenConnect and Automate.

NOC-tested Windows patchesScreenConnect built inQuote only
Intel page →
ConnectWise logo
Quote

quote-only; hosted on your own Windows server with MySQL or in ConnectWise’s cloud — ConnectWise’s own FAQ calls it a separate tool from ConnectWise RMM

MSPs that want the deepest scripting and automation in the ConnectWise range and need to host the RMM on their own server — the self-hosted route for data kept in India.

The catch: ConnectWise says it “primarily supports Windows”; self-hosting means you patch the Automate server yourself (several critical fixes since 2024), and prices are quote-only.

Self-hosted or cloudDeep scriptingWindows-first
Intel page →
Datto logo
Quote

quote-only standalone (third-party patching, Advanced Software Management, is a separate licence there); also the RMM inside Kaseya 365 Endpoint, reported at $5.25 (Pro) or $2.25 (Express) per endpoint a month with a 50-endpoint minimum, which includes it

MSPs that want a cloud RMM with Windows patching, ransomware detection and Microsoft 365 user management, sold together with Datto backup and Kaseya security.

The catch: Cloud-only on AWS with no India platform (Ireland, US and Sydney); native patching is Windows-only (Macs via a component, Linux not documented); phones and tablets are not in the console today — native Apple MDM is announced for October 2026.

Kaseya 365 bundleThird-party patchingQuote only
Intel page →
Kaseya logo
Quote

per device, quote-only; third-party patching is a separate per-device licence; also an RMM option inside Kaseya 365 Endpoint; SaaS or on-premises

MSPs and internal IT teams that want an RMM they can run SaaS or on their own Windows server, with policy-driven OS and third-party patching, standard-language scripting and Android Enterprise management in the same console.

The catch: Quote-only, and the PSA (Kaseya BMS or Autotask) is a separate product; Kaseya sells a second RMM, Datto RMM, so check which one your bundle includes; an on-premises server is yours to harden and patch — the 2021 REvil attack exploited zero-days in on-prem VSA 9.5.

SaaS or on-premThird-party patching add-onAndroid Enterprise
Intel page →
Heimdal logo

per device / year, quoted — OS and 350+ third-party application updates on Windows, macOS and Ubuntu from Heimdal’s cloud dashboard, with software inventory

Teams that want patching and asset inventory from the same agent as Heimdal’s DNS filtering and antivirus.

The catch: Not an RMM: no PSA, scripting-led remote management or mobile devices; Linux has no agent interface; quote-only, and tenant data stays in Europe, the US or the UK.

350+ third-party appsWindows / macOS / UbuntuNot an RMM
Intel page →
WatchGuard logo

per endpoint, quoted — an add-on module to WatchGuard Endpoint Security, patching Windows, macOS and Linux and third-party applications from WatchGuard Cloud

WatchGuard Endpoint Security estates that want OS and application patching in the same agent and console.

The catch: Not sold on its own and not an RMM: no PSA, scripting or mobile patching; no price is published and WatchGuard Cloud has no Indian region.

Endpoint add-onWindows / macOS / LinuxNot an RMM
Intel page →
Absolute logo

per device / year; patching starts at the Resilience for Security edition ($79.95 MSRP) and Resilience for Automation ($89.95) adds vulnerability fixes, workflows and remote control; both MSRPs are private-offer-only list figures on Absolute's AWS Marketplace listing

PC fleets that want OS and third-party patching on the same firmware-anchored agent that keeps security tools running and laptops recoverable, often beside Intune.

The catch: Not an RMM or MDM: no phones or tablets, no PSA; patching needs the top two editions; Linux patching is claimed on a product page but missing from the agent's published requirements; quote-led.

Firmware-anchored agentPatching in top editionsNot an RMM
Intel page →
Why each constraint rules out what it doesShow the reasoning ↓

Per technician, unlimited devicesRules out Qualys Patch Management, NinjaOne Patch Management, SuperOps Patch Management, Action1 Software Deployment, Action1 Vulnerability Remediation, LogMeIn Central, NinjaOne RMM, SuperOps RMM, N-able N-central, N-able N-sight, Action1, Action1 RMM & Remote Access, ManageEngine Endpoint Central, Splashtop AEM, LogMeIn Resolve, TeamViewer Remote Management, ConnectWise RMM, ConnectWise Automate, Datto RMM, Kaseya VSA 10, Heimdal Patch & Asset Management, WatchGuard Patch Management and Absolute Secure Endpoint (Resilience for Security / Automation) — priced per device / endpoint, not per technician. That leaves Atera RMM.

Per device or endpointRules out Atera RMM — priced per technician, not per device. That leaves Qualys Patch Management, NinjaOne Patch Management, SuperOps Patch Management, Action1 Software Deployment, Action1 Vulnerability Remediation, LogMeIn Central, NinjaOne RMM, SuperOps RMM, N-able N-central, N-able N-sight, Action1, Action1 RMM & Remote Access, ManageEngine Endpoint Central, Splashtop AEM, LogMeIn Resolve, TeamViewer Remote Management, ConnectWise RMM, ConnectWise Automate, Datto RMM, Kaseya VSA 10, Heimdal Patch & Asset Management, WatchGuard Patch Management and Absolute Secure Endpoint (Resilience for Security / Automation).

Free to startRules out Qualys Patch Management, NinjaOne Patch Management, SuperOps Patch Management, LogMeIn Central, NinjaOne RMM, Atera RMM, SuperOps RMM, N-able N-central, N-able N-sight, Splashtop AEM, LogMeIn Resolve, TeamViewer Remote Management, ConnectWise RMM, ConnectWise Automate, Datto RMM, Kaseya VSA 10, Heimdal Patch & Asset Management, WatchGuard Patch Management and Absolute Secure Endpoint (Resilience for Security / Automation) — no free tier (trial only). That leaves Action1 Software Deployment, Action1 Vulnerability Remediation, Action1, Action1 RMM & Remote Access and ManageEngine Endpoint Central.

On-prem or India data residencyRules out Qualys Patch Management, NinjaOne Patch Management, SuperOps Patch Management, Action1 Software Deployment, Action1 Vulnerability Remediation, LogMeIn Central, NinjaOne RMM, Atera RMM, SuperOps RMM, N-able N-central, N-able N-sight, Action1, Action1 RMM & Remote Access, Splashtop AEM, LogMeIn Resolve, TeamViewer Remote Management, ConnectWise RMM, Datto RMM, Heimdal Patch & Asset Management, WatchGuard Patch Management and Absolute Secure Endpoint (Resilience for Security / Automation) — cloud-only, no on-prem and no India data region. That leaves ManageEngine Endpoint Central, ConnectWise Automate and Kaseya VSA 10.

Ticketing or PSA in the consoleRules out Qualys Patch Management, NinjaOne Patch Management, Action1 Software Deployment, Action1 Vulnerability Remediation, LogMeIn Central, N-able N-central, N-able N-sight, Action1, Action1 RMM & Remote Access, ManageEngine Endpoint Central, Splashtop AEM, TeamViewer Remote Management, ConnectWise RMM, ConnectWise Automate, Datto RMM, Kaseya VSA 10, Heimdal Patch & Asset Management, WatchGuard Patch Management and Absolute Secure Endpoint (Resilience for Security / Automation) — no ticketing in the console (a separate service-desk product). That leaves SuperOps Patch Management, NinjaOne RMM, Atera RMM, SuperOps RMM and LogMeIn Resolve.

Backup from the same vendorRules out Qualys Patch Management, SuperOps Patch Management, Action1 Software Deployment, Action1 Vulnerability Remediation, LogMeIn Central, SuperOps RMM, Action1, Action1 RMM & Remote Access, ManageEngine Endpoint Central, Splashtop AEM, LogMeIn Resolve, ConnectWise Automate, Heimdal Patch & Asset Management, WatchGuard Patch Management and Absolute Secure Endpoint (Resilience for Security / Automation) — no backup product; Atera RMM, Datto RMM and Kaseya VSA 10 — backup via third-party integration, not a vendor SKU. That leaves NinjaOne Patch Management, NinjaOne RMM, N-able N-central, N-able N-sight, TeamViewer Remote Management and ConnectWise RMM.

Linux in the fleetRules out Action1 Software Deployment, Action1 Vulnerability Remediation, LogMeIn Central, Splashtop AEM, LogMeIn Resolve, TeamViewer Remote Management, ConnectWise RMM, ConnectWise Automate, Datto RMM and Absolute Secure Endpoint (Resilience for Security / Automation) — patches Windows and macOS only (Linux is remote-control at best). That leaves Qualys Patch Management, NinjaOne Patch Management, SuperOps Patch Management, NinjaOne RMM, Atera RMM, SuperOps RMM, N-able N-central, N-able N-sight, Action1, Action1 RMM & Remote Access, ManageEngine Endpoint Central, Kaseya VSA 10, Heimdal Patch & Asset Management and WatchGuard Patch Management.

Phones and tablets in scopeRules out Qualys Patch Management, Action1 Software Deployment, Action1 Vulnerability Remediation, LogMeIn Central, N-able N-central, N-able N-sight, Action1, Action1 RMM & Remote Access, Splashtop AEM, TeamViewer Remote Management, ConnectWise RMM, ConnectWise Automate, Datto RMM, Heimdal Patch & Asset Management, WatchGuard Patch Management and Absolute Secure Endpoint (Resilience for Security / Automation) — no mobile device management; Atera RMM — mobile only through a separate Miradore subscription and console. That leaves NinjaOne Patch Management, SuperOps Patch Management, NinjaOne RMM, SuperOps RMM, ManageEngine Endpoint Central, LogMeIn Resolve and Kaseya VSA 10. It flags NinjaOne Patch Management — Mobile is a paid MDM add-on to the same console, SuperOps Patch Management — Mobile is a paid MDM add-on to the same console, NinjaOne RMM — Mobile is a paid MDM add-on to the same console and SuperOps RMM — Apple and Android MDM sits in the higher Prime Plus tier, not the base plan — marked on the cards, not removed.

Under 100 endpointsRules out SuperOps Patch Management, SuperOps RMM, Splashtop AEM and TeamViewer Remote Management — published 100-endpoint minimum. That leaves Qualys Patch Management, NinjaOne Patch Management, Action1 Software Deployment, Action1 Vulnerability Remediation, LogMeIn Central, NinjaOne RMM, Atera RMM, N-able N-central, N-able N-sight, Action1, Action1 RMM & Remote Access, ManageEngine Endpoint Central, LogMeIn Resolve, ConnectWise RMM, ConnectWise Automate, Datto RMM, Kaseya VSA 10, Heimdal Patch & Asset Management, WatchGuard Patch Management and Absolute Secure Endpoint (Resilience for Security / Automation). It flags NinjaOne RMM — No published minimum, but NinjaOne’s top rate ($3.75 per device) applies at 50 or fewer endpoints — marked on the cards, not removed.

2,000+ endpointsRules nothing out on published terms. It flags SuperOps Patch Management — Unverified above 2,000 endpoints, Atera RMM — Unverified above 2,000 endpoints, SuperOps RMM — Unverified above 2,000 endpoints, Action1 — Unverified above 2,000 endpoints, Action1 RMM & Remote Access — Unverified above 2,000 endpoints, Splashtop AEM — Unverified above 2,000 endpoints, LogMeIn Resolve — Unverified above 2,000 endpoints, TeamViewer Remote Management — Unverified above 2,000 endpoints, ConnectWise Automate — Unverified above 2,000 endpoints, Heimdal Patch & Asset Management — Unverified above 2,000 endpoints and WatchGuard Patch Management — Unverified above 2,000 endpoints — marked on the cards, not removed.

Separate business units or tenantsRules out LogMeIn Central and ManageEngine Endpoint Central — multi-tenant is the separate Endpoint Central MSP edition; Atera RMM — IT-department plans are single-organisation; multi-tenant is the MSP plan. That leaves Qualys Patch Management, NinjaOne Patch Management, SuperOps Patch Management, Action1 Software Deployment, Action1 Vulnerability Remediation, NinjaOne RMM, SuperOps RMM, N-able N-central, N-able N-sight, Action1, Action1 RMM & Remote Access, Splashtop AEM, LogMeIn Resolve, TeamViewer Remote Management, ConnectWise RMM, ConnectWise Automate, Datto RMM, Kaseya VSA 10, Heimdal Patch & Asset Management, WatchGuard Patch Management and Absolute Secure Endpoint (Resilience for Security / Automation). It flags Splashtop AEM — Tenant separation not documented either way, LogMeIn Resolve — Tenant separation not documented either way, TeamViewer Remote Management — Tenant separation not documented either way, Heimdal Patch & Asset Management — Tenant separation not documented either way, WatchGuard Patch Management — Tenant separation not documented either way and Absolute Secure Endpoint (Resilience for Security / Automation) — Tenant separation not documented either way — marked on the cards, not removed.

Windows and macOS in the fleetRules nothing out. All seven patch Windows and macOS. What differs is depth: the macOS third-party catalog ranges from hundreds of apps (LogMeIn Resolve lists ~100 on macOS, TeamViewer and ManageEngine hundreds across both) down to roughly 30 on Action1, and Atera's depends on what Homebrew carries.

Remote access includedRules nothing out — every product here ships remote control (NinjaOne via Splashtop / ScreenConnect in its bundle, Atera via Splashtop and AnyDesk, Action1 built in, ManageEngine built in, and the three remote-first vendors natively). The double-buy question is the other way round: if you already hold one of the three remote tools, their RMM tier may be enough.

Scripting depthRules nothing out on documentation — all seven run scripts across endpoints. Depth differs: NinjaOne, Atera (library + AI-generated) and Action1 document automation at policy level; Splashtop AEM and Resolve document scripting; TeamViewer's is thinnest. Where the line falls for your runbooks is a PoC question, not a datasheet one.

100–2,000 endpointsRules nothing out: the published minimums (Splashtop AEM and TeamViewer ONE at 100, NinjaOne publishes none) are cleared, and no product publishes a ceiling in this band. Which console starts to strain first is delivery-team experience: [TechBag to confirm].

Endpoint security from the same vendorNot offered as a chip because the line between 'sells an EDR SKU' and 'integrates one' is blurred in every datasheet. NinjaOne resells endpoint security and integrates CrowdStrike / SentinelOne / Bitdefender; ManageEngine's Security edition adds vulnerability and ransomware controls; TeamViewer and Splashtop sell antivirus add-ons; Atera resells third-party AV. Read the agent-coexistence block before treating any of it as a second EDR.

Narrow to your situation

Eight situations, eight shortlists — and why

The names alone would be a vendor list. The reasoning is what you can check against your own estate.

Internal IT, 200–2,000 mostly-Windows endpoints, no MSP

Why: Catalog-based patching with approval rings and a console built for one organisation; NinjaOne for breadth, Action1 for patch-first simplicity, ManageEngine if UEM depth or on-prem matters.

The trade-off: NinjaOne publishes only a price band and quotes the exact rate; Action1's monitoring is lighter than a full RMM; ManageEngine's console carries its Windows-first heritage.

Two technicians, 800 devices — headcount is tiny, the fleet is not

Why: Per-technician pricing (Atera) or a free-to-200 / per-50-endpoint model makes the bill track the team, not the estate.

The trade-off: Atera charges for every login and its add-ons stack; Action1 jumps to $4 per endpoint beyond 200 plus support; ManageEngine charges for technicians beyond the first.

Patch compliance is the whole job — audits ask for proof

Why: Vulnerability-to-patch views, per-CVE evidence and exportable reports; Action1 and ManageEngine are built around the patch record, NinjaOne reports across the estate.

The trade-off: An RMM's 'patched' is not a UEM's 'compliant' — if the audit asks for device state (encryption, configuration, enrolment), you still need a UEM beside it.

Windows + macOS + Linux servers, one console

Why: Documented Linux patching — NinjaOne and Action1 by catalog, Atera by APT on Ubuntu / Debian — alongside Windows and macOS.

The trade-off: macOS third-party coverage varies widely (Action1 ~30 apps; Atera depends on Homebrew); test your top 20 apps on every OS in the PoC.

You already pay for Splashtop, TeamViewer or LogMeIn

Why: Their RMM tiers ride the agent you already run — no second agent, no second contract, and the double-buy disappears.

The trade-off: All three patch Windows and macOS only, two carry 100-endpoint minimums, and monitoring / scripting depth is below NinjaOne, Atera or Action1.

Separate business units that must not see each other

Why: NinjaOne and Action1 document scoped organisations in one console; Atera does it on the MSP plan.

The trade-off: On Atera's IT-department plans and on Endpoint Central (non-MSP) the separation is a different plan or edition — price that SKU, not the one on the website.

UEM and RMM in one console — phones too

Why: ManageEngine's UEM edition, NinjaOne's MDM add-on and Resolve's built-in MDM put mobile beside the RMM agent.

The trade-off: Depth differs sharply: ManageEngine is a full UEM, NinjaOne MDM is Apple / Android without Windows MDM, Resolve MDM is light — see the UEM & MDM guide for the mobile side.

Regulated — on-prem or India data residency is mandatory

Why: The only product here with an on-premises edition and an India data centre; the other six are cloud-only in US / EU / other regions.

The trade-off: One survivor means no competitive tension on price — TechBag negotiates edition and technician count instead, and checks whether a cloud region you can accept reopens the field.

The spine of the decision

“Patches third-party apps” means three different things

Every product here ticks the box. The mechanism underneath decides which of your applications actually get patched, on which OS, and how much of the work is yours. Then the pipeline itself — five stages, and the two where buyers get hurt.

Mechanism 1

Curated catalog, every OS

The vendor packages and tests the updates; you approve. Windows, macOS and Linux covered from one catalog — the depth of the macOS list is the thing to check (Action1’s is ~30 apps; NinjaOne’s and ManageEngine’s run to hundreds).

Mechanism 2

Curated catalog, Windows + macOS

Same model, two platforms: LogMeIn Resolve lists ~450 products (≈350 Windows, ≈100 macOS), TeamViewer ‘hundreds’, Splashtop AEM OS plus third-party. Linux is remote-control at most.

Mechanism 3

Package managers

Atera patches third-party software through WinGet and Chocolatey on Windows, Homebrew on macOS and APT on Linux. Breadth is whatever those repositories carry; testing is the community’s, not the vendor’s — flexible, and yours to own.

Pipeline

Five stages — two of them are where it goes wrong

Stage 01

Detect

The agent inventories installed software and missing updates. Cadence and coverage decide how stale the picture is.

Every product

Stage 02

Approve

Who decides what ships, and how that maps to your change-control calendar. Auto-approve by severity, manual by ring, or a maintenance window — the workflow either matches your CAB or fights it.

The first failure point

Stage 03

Ring

Pilot → broad → everyone. Deploy by group with a bake time between rings; the console must let you stop a ring mid-flight.

Every product, varying granularity

Stage 04

Reboot

The patch is not applied until the machine restarts. Deferral windows, user prompts and forced reboots after N days are policy — and the second place buyers discover the product’s limits.

The second failure point

Stage 05

Verify

Post-reboot confirmation, per-CVE evidence, exportable reports. An RMM’s report proves the patch; it does not prove the device’s configured state — that is a UEM’s job.

Depth varies most

Agent coexistence

Three agents on one laptop is normal. Two EDRs is not.

  • —RMM + UEM + EDR coexist by design — different jobs, different kernel footprints. Exclusions go both ways: the EDR must trust the RMM agent’s scripts and installers, the RMM must not try to update the EDR.
  • —The RMM’s “endpoint security” is usually a resold or integrated EDR (NinjaOne with CrowdStrike / SentinelOne / Bitdefender; TeamViewer and Splashtop with antivirus add-ons). Deploy it beside an EDR you already run and you have two real-time engines fighting over the same files.
  • —Ask in the PoC: which EDRs has the vendor documented exclusions for, and can the RMM deploy and watch the EDR agent without managing it.

Alert volume

The console that alerts on everything gets closed.

  • —Default monitoring policies fire on disk, CPU, services and events for every device on day one. At 500 endpoints that is thousands of alerts a week until someone tunes thresholds per device class — and nobody does until the console is already ignored.
  • —What to test: can a policy be scoped by group and inherited, can an alert auto-remediate with a script before it pages a human, and can you see alert counts per policy to find the noisy one.
  • —Budget the tuning as implementation, not as a bug. Which vendors’ defaults are quietest for your device mix is delivery-team experience: [TechBag to confirm].
What breaks as you grow

Scale behaviour — 200, 2,000, 10,000 endpoints

The datasheet is the same at every size. What changes is which part of the pipeline becomes the bottleneck — and at 2,000 the pricing model itself starts to decide the bill.

200endpoints

Workflow becomes the constraint

  • —Manual approval still works — but the approval calendar must already match change control, or every patch Tuesday is a negotiation.
  • —One technician knows the console; scripts live in that person’s head. A shared library and naming convention are a control, not tidiness.
  • —Free tiers and minimums bite here: Action1 is free to 200, Splashtop AEM and TeamViewer ONE start at 100.

Put this in your PoC

Run one full patch cycle with approval, two rings and a forced reboot; time it end to end.

2,000endpoints

Noise and money become the constraint

  • —Alert volume outruns the team unless policies are scoped per device class; ring deployment is now mandatory, never fleet-wide.
  • —Per-device bills are now large numbers; per-technician bills are not. This is where the model flips the decision.
  • —Multi-site or multi-unit scoping stops being optional — who may see and act on which devices.

Put this in your PoC

Push a patch to a 200-device ring and measure time-to-90% installed and rebooted; count alerts per policy for a week.

10,000endpoints

The console and the API are the constraint

  • —Search, bulk actions and reporting latency decide how fast you can move; API rate limits decide what you can automate around the console.
  • —Delegated administration by region or business unit is mandatory; audit trails of who ran what script where become a compliance artefact.
  • —Agent upgrades themselves need rings. A bad agent release across 10,000 machines is the worst day an RMM can give you.

Put this in your PoC

Bulk-script 1,000 devices; pull the full inventory through the API; confirm documented throughput, not a sales claim.

Category-wide behaviours. NinjaOne and ManageEngine document estates well above 2,000 endpoints; the other five are marked unverified at that size in the instrument, not ruled out. Where a specific console strains for your fleet: [TechBag to confirm].

The switching cost

Switching RMM is cheaper than switching UEM — and still not free

An RMM agent is not an enrolment. You can push the new agent with the old RMM, then retire the old one — no wipe, no re-enrolment, no hands on devices. The cost is everything you built in the console, which does not travel:

The agent

Deploy the new agent as a package through the old RMM, verify check-in, uninstall the old. Scriptable across the estate.

Exit costScriptable

Policies, alert rules, scripts

Monitoring thresholds, patch approval rules, automation and the script library are rebuilt by hand — there is no import format between vendors.

Exit costRebuild

Patch history and evidence

Compliance reports and per-device patch history stay in the old console. Export before the contract ends, or the audit trail ends with it.

Exit costExport or lose

Bundled tools

Remote access, backup and any resold security that rode on the old licence need their own replacement or re-licence — the double-buy in reverse.

Exit costRe-licence

The exception is a product that is also your UEM (ManageEngine) or carries your MDM (NinjaOne, Resolve) — the mobile side then follows the UEM rules, including re-enrolment.

Rebuild effort in days for your console: [TechBag to confirm] — TechBag scopes it from your policy count, script library and alert rules.

What it costs

Per technician or per device — the hard comparison

First the cheaper question — whether a licence you hold already does the job. Then the comparison nobody can do from a price list: the same fleet, worked at 200, 500 and 2,000 endpoints, in USD and INR. Then what the licence line leaves out.

01

Do you already own one?

Four things you may already pay for patch or monitor. None of them is the whole RMM job; one of them may be enough.

Microsoft 365
Partly Windows Autopatch (E3, E5, Business Premium, A3/A5) patches Windows and Microsoft 365 apps on rings. No third-party apps, no monitoring, no scripting, no macOS or Linux.
Your UEM
Sometimes ManageEngine Endpoint Central is both. Intune patches the OS and Store / Enterprise-App-Management apps; Jamf patches Macs. None of them monitors or remediates at RMM depth.
Your remote-access tool
Often Splashtop AEM, TeamViewer ONE Advanced and LogMeIn Resolve add patching, monitoring and scripting to the agent you already run — Windows and macOS only.
Your EDR
Rarely Vulnerability visibility, yes; patch deployment, only in the newer ‘for IT’ modules. Check before assuming, and never let it become a second patch authority.

If the tool you already pay for does the job, we say so before the quote — not after.

02

The same fleet at 200, 500 and 2,000 endpoints

Monthly licence cost from published list prices, annual terms, INR at ≈₹83/$ for scale. Technician headcount is an assumption — 1, 2 and 5 respectively — because per-technician pricing depends on it; your real number is [TechBag to confirm]. Quote-only products are shown at their reported midpoint or left as a quote.

200endpoints · 1 technician
  • Atera$149 ≈₹12,367
  • Splashtop AEM$200 ≈₹16,600
  • ManageEngine Endpoint Central$265 ≈₹21,995
  • SuperOps (Prime)$280 ≈₹23,240
  • NinjaOne RMM$600 ≈₹49,800
  • Absolute Secure EndpointQuote
  • WatchGuard Patch ManagementQuote
  • Heimdal Patch & Asset ManagementQuote
  • Action1Quote
  • LogMeIn ResolveQuote
  • TeamViewer Remote ManagementQuote
  • N-able N-centralQuote
  • N-able N-sightQuote
  • ConnectWise RMMQuote
  • Datto RMMQuote
  • Kaseya VSA 10Quote

per month · licence only

500endpoints · 2 technicians
  • Atera$298 ≈₹24,734
  • Splashtop AEM$500 ≈₹41,500
  • ManageEngine Endpoint Central$663 ≈₹55,029
  • SuperOps (Prime)$700 ≈₹58,100
  • NinjaOne RMM$1,500 ≈₹1,24,500
  • Absolute Secure EndpointQuote
  • WatchGuard Patch ManagementQuote
  • Heimdal Patch & Asset ManagementQuote
  • Action1Quote
  • LogMeIn ResolveQuote
  • TeamViewer Remote ManagementQuote
  • N-able N-centralQuote
  • N-able N-sightQuote
  • ConnectWise RMMQuote
  • Datto RMMQuote
  • Kaseya VSA 10Quote

per month · licence only

2,000endpoints · 5 technicians
  • Atera$745 ≈₹61,835
  • Splashtop AEM$2,000 ≈₹1,66,000
  • SuperOps (Prime)$2,400 ≈₹1,99,200
  • ManageEngine Endpoint Central$2,650 ≈₹2,19,950
  • NinjaOne RMM$6,000 ≈₹4,98,000
  • Absolute Secure EndpointQuote
  • WatchGuard Patch ManagementQuote
  • Heimdal Patch & Asset ManagementQuote
  • Action1Quote
  • LogMeIn ResolveQuote
  • TeamViewer Remote ManagementQuote
  • N-able N-centralQuote
  • N-able N-sightQuote
  • ConnectWise RMMQuote
  • Datto RMMQuote
  • Kaseya VSA 10Quote

per month · licence only

Basis of each line

  • —Absolute Secure Endpoint: per device a year; private-offer MSRPs $79.95 (Resilience for Security) and $89.95 (Resilience for Automation), quoted in practice.
  • —WatchGuard Patch Management: quote-only per endpoint, as an add-on to a WatchGuard Endpoint Security licence.
  • —Heimdal Patch & Asset Management: quote-only per device a year; Heimdal publishes no price.
  • —Atera: Professional, $149 per technician / mo, annual.
  • —Action1: first 200 endpoints free; above that Action1 publishes NO price at all — only a request-a-quote form — and a mandatory support fee applies. Third parties report ~$4 per endpoint / mo, but the vendor does not confirm it, so it is shown unpriced.
  • —ManageEngine Endpoint Central: Professional on-prem, $795 per 50 endpoints a year (≈ $1.33 / endpoint / mo); one technician included.
  • —Splashtop AEM: vendor-stated ceiling of $1 per endpoint / mo; 100-endpoint minimum.
  • —LogMeIn Resolve: per endpoint, billed annually, 25-endpoint minimum (patching needs Advanced or Complete); GoTo draws the dollar figures in the browser, so it is shown unpriced — TechBag confirms today’s per-endpoint price.
  • —NinjaOne RMM: NinjaOne publishes a band — $3.75 per device / mo at 50 or fewer endpoints down to $1.50 at 10,000 — and quotes the exact rate; shown at an illustrative $3.
  • —SuperOps (Prime): PUBLISHED internal-IT rate: $1.50 per endpoint / mo at the 100 minimum, $1.40 (101–500), $1.30 (501–1,000), $1.20 (1,000+); service desk included (MSP plans are per technician instead).
  • —TeamViewer Remote Management: quote-only per endpoint, annual; 100-endpoint minimum.
  • —N-able N-central: quote-only; third parties REPORT ~$1.50–3.50 per device / mo by volume and bundle — shown unpriced because those are not N-able figures.
  • —N-able N-sight: quote-only; reported below N-central, no published rate card.
  • —ConnectWise RMM: quote-only — three packages, no public price.
  • —Datto RMM: quote-only standalone; reported at $5.25 per endpoint a month inside Kaseya 365 Endpoint Pro (50-endpoint minimum).
  • —Kaseya VSA 10: quote-only per device; third-party patching is a separate per-device licence.

Read across, not down: at 200 endpoints the free tier and the per-technician seat tie for cheapest; at 2,000 the per-technician model is a fraction of every per-device line — unless your team is large, in which case it isn’t. Atera’s add-ons ($29 ≈ ₹2,407 each per technician) and Action1’s support subscription sit outside these numbers.

TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale; the tier-matched INR quote — and the technician count that makes the per-seat line real — is ours.

03

What the licence line leaves out

Add-ons and seats

Atera: every login is a seat, and Network Discovery is $29 ≈ ₹2,407 per technician (AI Copilot moved into every plan with the 2026 repricing). NinjaOne: MDM, backup and endpoint security are separate SKUs. ManageEngine: one technician per edition, the rest paid. Action1: a support subscription is mandatory past 200. Price the console you will actually run, not the entry row.

Minimums and floors

Splashtop AEM and TeamViewer ONE start at 100 endpoints and LogMeIn Resolve at 25; NinjaOne publishes no minimum but charges the top of its band, $3.75 per device, at 50 or fewer endpoints. Under those sizes the minimum, not the rate, is the bill — and a free tier (Action1 to 200, ManageEngine to 25) may be the honest answer.

The UEM you still need

If the requirement behind the purchase is compliance evidence — encryption, configuration, enrolment state — the RMM bill is half the bill. ManageEngine covers both in one product; everywhere else, budget the UEM beside it, or accept that the green dashboard answers a different question.

Before you commit

What goes wrong — the failure modes we can document

Drawn from vendor documentation and published behaviour; each is being matched to real TechBag engagements before it is presented as a case. Read them before the demo, not after the contract.

The approval workflow doesn’t match change control

Auto-approve-by-severity is fine until the CAB wants every production patch in a window. If the console can’t model your calendar, the team approves by hand forever — or turns automation off.

Third-party coverage varies wildly

Action1’s macOS catalog is ~30 apps; Resolve lists ~100 on macOS; Atera’s depends on what Homebrew and Chocolatey carry. ‘Patches third-party apps’ is true of all seven and means something different each time.

The RMM’s security add-on fights your EDR

Resold or integrated endpoint security is a second real-time engine. Deployed beside an EDR you already run, both lose. Document exclusions both ways or pick one.

Alert volume makes the console unusable

Default policies fire on everything. Untuned, the console becomes noise within weeks and stops being opened — the most common reason an RMM quietly fails.

Every login is a paid seat

Per-technician pricing has no read-only tier at Atera; ManageEngine bills technicians past the first. A helpdesk that ‘just needs to look’ is a licence line.

The free tier has a cliff

Action1 is free to 200 with no feature limits; endpoint 201 puts the whole estate on $4 per endpoint plus support. Plan the crossing, don’t discover it.

Windows-first heritage shows up on the Mac and the phone

macOS third-party depth and mobile coverage trail Windows across most of the category; three products don’t patch Linux at all. Test your non-Windows top twenty in the PoC.

Green dashboard, failed audit

The RMM reported every device patched and responsive. The auditor asked for encryption, configuration and enrolment state. Different question, different tool — and the most expensive surprise in this category.

Three doors — pick by where you are

Researching

See the whole landscape and where each product sits.

Endpoint-management map →

Evaluating

Get your shortlist scoped against your real fleet.

Scope my shortlist →

Buying

Tier-matched USD + INR quote with GST.

Get a quote →

Vendor-neutral. No gated content.