Your Macs already run one agent for management. Security shouldn’t need a second one — Iru EDR switches detection on inside the Iru agent your Macs and PCs already run — behavioural Protect mode on macOS, file scanning in Detect mode on Windows.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Iru EDR — the detection and response add-on for Mac and Windows. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Detection and response that runs inside the device-management agent you already have, licensed as an add-on instead of a second product.
What consolidation actually replaces, dimension by dimension.
| Dimension | A management agent plus separate antivirus | Iru EDR |
|---|---|---|
| Agents on a Mac | One to manage it, one more for security | One Iru agent doing both jobs |
| A malicious Mac process | Noticed after the damage is done | Ended and its file quarantined in Protect mode |
| A suspect laptop | Someone asks the user to unplug it | Isolated from the network from the console |
| USB sticks on the Mac fleet | A written policy nobody enforces | Accessory & Storage Access rules |
| Detection logs for the SOC | Screenshots pasted into a ticket | An Amazon S3 export your SIEM ingests |
| What it is NOT | — | Windows behaviour rules, Linux, rollback or MDR |
The cheapest test is the free trial: put ten Macs in Protect mode, allow-list your in-house tools, and see what the engine flags in two weeks.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The agent that applies settings and updates for Iru Endpoint Management also carries the detection engine, so switching EDR on needs no second installer on the machine.
Detection settings travel as a Library Item scoped through Blueprints; Iru’s documentation says the EDR add-on licence is required before that item can be used at all.
On macOS the engine reads events from Apple’s Endpoint Security framework and judges both files and process behaviour; Protect mode then ends the process and quarantines the file.
Windows 11 machines under Iru get file-based scanning that flags malware and potentially unwanted programs, with no behavioural layer and no automatic quarantine of what it finds.
One agent for management and detection — an EDR Library Item decides whether a Mac protects or a PC just reports.
Iru EDR adds detection and response to the agent that already manages your Macs and Windows PCs.
Mac detection looks at what a running process does as well as at the file on disk, using events from Apple’s Endpoint Security framework.
File-based detection runs on macOS and Windows alike and raises known malware and potentially unwanted programs it finds on a device.
Put Macs in Protect mode and a detected process is stopped and its file moved to quarantine; Windows devices stay in Detect mode and only report.
Device isolation is listed among the Mac response actions, so a suspect laptop can be cut off from the network while someone investigates it.
Allow and block list entries let admins stop an in-house tool from being flagged and make sure a banned binary is always treated as a threat.
Accessory & Storage Access controls set what removable media a Mac will accept, managed from the same console as the rest of the policy.
Iru’s 2025 overview of the EDR add-on, a 2026 customer session on reaching ISO 27001 with endpoint security, and a 2025 episode on Mac malware with Patrick Wardle. All from Iru’s official channel.
Iru’s own walkthrough of the EDR add-on, recorded for the October 2025 launch of the Iru name.
A customer session on using endpoint security controls as evidence on the way to an ISO 27001 certificate.
A conversation with Mac security researcher Patrick Wardle on how macOS malware and its defenders keep adapting.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Iru EDR is not another installer to push. The agent that already enforces settings and OS updates on your Macs and Windows PCs takes on the detection engine once the add-on is licensed and the EDR Library Item is assigned, so an existing Iru Endpoint Management customer turns it on from the console the team already uses.
On macOS Iru combines file and behavioural detection on Apple’s Endpoint Security framework, and Protect mode ends the offending process and quarantines its file. Allow and block lists, device isolation and removable-media rules sit alongside. Planning Center, per Iru’s customer story, moved to it after running SentinelOne.
Iru’s product page says the engine stops 2.3x more zero-day exploits and uses 22% fewer resources, yet it names no AV-TEST run, MITRE evaluation or other test behind either number. Treat both as marketing, and let a pilot on your own Macs show the detection results and CPU load you will actually live with.
On Windows the engine only scans files in Detect mode, reporting malware and PUPs without ever quarantining them, and no behaviour rules apply. There is no Linux agent, no mobile coverage, no file rollback and no MDR service. Each tenant is hosted in America or Germany, and help desks answer 24/5 rather than around the clock.
List how many Macs and Windows 11 machines need cover, because Windows gets Detect mode only and is licensed apart.
Assign the EDR Library Item to a pilot Blueprint of IT and developer Macs, plus a few PCs, while Protect mode stays off.
Add allow-list entries for in-house tools the engine flags, then move pilot Macs into Protect mode and watch the queue.
Send detections to an Amazon S3 bucket, point the SIEM at it, and decide who answers alerts outside 24/5 support.
Extend EDR to the whole fleet, apply storage access rules to sensitive teams, and sign the annual contract in INR.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We already ran Iru on 400 MacBooks, so EDR was one Library Item and a licence change. No new agent, no rollout project.”
“Protect mode killed an infostealer a designer pulled in with a cracked font tool, and the file was in quarantine before lunch.”
“Our 30 Windows laptops only get Detect mode. It tells us about malware but someone still has to clean each one up by hand.”
“Blocking USB storage on finance Macs from the same console we use for updates closed an audit finding in an afternoon.”
“We pull detections from the S3 export into our SIEM. Plan the bucket and the parser early; it is not a native connector.”
“Support hours suit us in Bengaluru on weekdays, but nobody answers on a Saturday night, so we keep our own on-call rota.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint protection market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Add-on to Iru’s MDM; quote-only, annual.
The grid nobody publishes — how many operating systems the agent fully covers vs how far it goes from an alert into containment and recovery.
macOS and Windows; Protect mode and isolation on Mac only.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Jamf Protect, CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint and Hexnode XDR — on platforms, Mac depth, response, price, managed service and India.
| Dimension | Iru EDR | Jamf Protect | CrowdStrike Falcon Insight XDR | SentinelOne Singularity Endpoint | Microsoft Defender for Endpoint | Hexnode XDR |
|---|---|---|---|---|---|---|
| What it is | Add-on EDR, Mac-first | Mac-native security | EDR grown into XDR | Autonomous EPP + EDR | EPP + EDR in two plans | XDR on a UEM agent |
| Deployment and agent | Same agent as MDM | Agent beside Jamf Pro | One Falcon sensor | One agent, cloud console | Built into Windows | Rides the UEM agent |
| Platforms covered | macOS and Windows 11 | Mac, plus mobile MTD | Windows, Mac, Linux | Windows, Mac, Linux | Five systems | Linux not documented |
| macOS detection | File + behavioural | MITRE-mapped analytics | Full Falcon on Mac | Behavioural AI on Mac | Present, Windows-led | Severity-scored alerts |
| Windows and Linux depth | Windows: Detect mode | Not covered | The same EDR everywhere | Full EDR, all three | Windows is the home turf | Not documented |
| Response and rollback | Mac: kill, isolate | Remediate through Pro | RTR, no rollback | One-click rollback | AIR, OneDrive restore | Isolate, restrict, wipe |
| Pricing model | Per device, annual | Per device, in plans | Per device, per year | Per endpoint, per year | Per user, per month | Per device, per month |
| Published entry price | Not published | Bundled, $12.50 a Mac | $184.99/device/year | From $179.99/year | $3 / $5.20 a month | $5.50/device/month |
| Included vs add-on | Needs the MDM licence | Mobile is in the box | XDR at no extra cost | Mobile and MDR extra | P1 lacks EDR | Requires Hexnode UEM |
| Managed service and support | No MDR; 24/5 support | No MDR on this page | Falcon Complete MDR | MDR as an add-on | Experts needs E5 | No managed service |
| SIEM and integrations | S3 export | Unified log streaming | 10 GB/day ingest | Storyline correlation | Native Sentinel | Inside the UEM console |
| India data region | US or EU only | No Indian hosting | Announced, not live | Mumbai region | India datacentres | Not verified |
| Lock-in and exit | Tied to Iru’s agent | Best beside Jamf Pro | Independent of MDM | Independent of MDM | Microsoft-shaped | Tied to Hexnode UEM |
| Best fit | Iru-managed Mac fleets | Jamf Pro shops | Teams that hunt | Rollback + India data | Microsoft 365 E5 estates | Hexnode UEM estates |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Iru EDR is one of 47 endpoint protection products TechBag carries. The Endpoint Protection guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (Macs and PCs covered; IT staff-hour cost). Estimates model the hours spent on each device a year chasing suspicious files, rebuilding infected laptops and babysitting a second security agent, assumed at 1.5 hours, of which 70% is assumed to go once detection lives in the management agent. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Iru publishes no EDR price: the add-on is licensed per device by platform on top of Iru Endpoint Management, on an annual contract billed annually, after a free 14-day trial. Per-device figures on review sites predate the current quote-only terms. TechBag counts Macs and Windows PCs separately first, then quotes in INR with GST.
Best for Apple-first fleets
Best for a broader rollout
Best for a few PCs beside the Macs
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
What share of devices are Macs? Windows gets file scanning in Detect mode only, and Linux has no agent at all.
Are your PCs on Windows 11 24H2 or later? Older Windows releases cannot be enrolled in Iru management.
Who cleans up a Windows detection by hand, given that nothing on Windows is quarantined automatically?
Iru runs no MDR and support is 24/5; which SOC or on-call rota answers an alert at 2 a.m. on a Sunday?
Can your SIEM read an Amazon S3 export, and who builds and maintains the parser for Iru’s detection data?
Is a US or EU tenant acceptable to your DPDP and customer contracts, since Iru offers no Indian region?
Will the pilot measure detection and CPU load yourself rather than relying on Iru’s 2.3x and 22% figures?
Is every agent at 4.7.5 or later, the build that fixed CVE-2026-39118, and kept current from then on?
Count your Macs and Windows PCs first, or let a TechBag advisor run the 14-day trial on a pilot group and get the add-on quoted in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.