B2B guide & comparison

Digital Business Card with MDM (Intune/Jamf): Distribution, Managed App Config and Provider Comparison

In large organizations, digital business cards rarely fail because of the card itself, but because of the rollout: anyone who wants to bring an app or a wallet pass to hundreds of managed company devices can hardly avoid Mobile Device Management (MDM), typically Microsoft Intune in combination with Entra ID (Azure AD). This is exactly where the market has to be assessed honestly: rolling out an app that sits in the App Store or Play Store is handled by the customer's own MDM (Microsoft Intune, Jamf) for any store app whatsoever.

The pure distribution is therefore a property of the operating system and the MDM platform, not a feature of the card provider. The actual, app-side differentiator is Managed App Configuration: whether the app accepts preconfigured settings (such as tenant or SSO) via MDM and thus starts without manual setup.

Precisely this app-side MDM and AppConfig support is publicly undocumented across the entire field and, by our strict standard, stands at "?" for all providers. In this comparison, we show how Intune, Entra ID, SSO, SCIM and Managed App Configuration differ from one another, why the pure distribution is generically possible for any store app, and what IT and data protection officers in the DACH region should pay attention to.

The order (oneVcard, Spreadly, Lemontaps) follows our weighted methodology of enterprise capabilities, GDPR compliance and overall rating; oneVcard is best positioned for an Intune scenario through its documented Microsoft Entra ID/Azure integration (SSO and user provisioning), but the concrete MDM device rollout is publicly undocumented here as well and must be confirmed with the provider before signing a contract.

Recommended providers for this use case

Sorted by overall score; the category-relevant sub-score is also shown per provider.

1

oneVcard

91 /100

Overall winner in the comparison: an ISO 27001 certified data center in Nürnberg, hosting and development exclusively in Germany, full enterprise package with SSO, user provisioning and dedicated signature management.

4.9 ⌀ external
  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 88/100

2

Spreadly

88 /100

Customer data on Hetzner in Germany according to the provider, delivery via EU infrastructure (including Bunny CDN), ISO 27001:2022, full enterprise provisioning (SSO/SCIM/HRIS), second-strongest GDPR score in the test (92); comparatively young company (founded 2022).

4.4 ⌀ external
  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 88/100

3

Lemontaps

87 /100

German enterprise competitor from Stuttgart with its own ISO 27001 certification (TÜV SÜD) and hosting on AWS Frankfurt.

4.8 ⌀ external
  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 82/100

4

Tapni

82 /100

Strong B2B provider with Frankfurt hosting and a broad enterprise feature set, though headquarters and development sit outside Germany

4.6 ⌀ external
  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 78/100

5

baningo cards

78 /100

Privacy-focused team solution from Austria with hosting in German ISO 27001 data centers

4.5 ⌀ external
  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 54/100

6

wazzl

77 /100

Privacy-focused digital business card from Bavaria: in-house German hosting to ISO 27001, SAML SSO and API, with limited pricing transparency.

  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 64/100

7

Blinq

76 /100

Australian market leader with top ratings and strong enterprise technology, but without guaranteed EU hosting.

4.8 ⌀ external
  • Hosting outside EU

Enterprise Integration (SSO/SCIM/MDM/API): 80/100

8

HiHello

76 /100

US provider with a deep enterprise feature set and top ratings, but purely US hosting.

4.7 ⌀ external
  • Hosting outside EU

Enterprise Integration (SSO/SCIM/MDM/API): 76/100

9

Popl

75 /100

US provider with strong integration and enterprise depth, but data storage in the USA/Canada and USD pricing.

4.5 ⌀ external
  • Hosting outside EU

Enterprise Integration (SSO/SCIM/MDM/API): 80/100

10
75 /100

US enterprise platform (formerly Beaconstac) with SOC 2, ISO 27001 and SCIM, but without EU hosting

4.5 ⌀ external
  • Hosting outside EU

Enterprise Integration (SSO/SCIM/MDM/API): 82/100

11

beCard

72 /100

Austrian SME all-rounder with München hosting and a genuine team offering

4.0 ⌀ external
  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 42/100

12

Mobilo

68 /100

US provider with a strong sales focus and an EU hosting option, but a thin GDPR and review situation

2.3 ⌀ external
  • EU hosting available

Enterprise Integration (SSO/SCIM/MDM/API): 72/100

13

Linq

62 /100

US provider with strong user ratings, but without EU hosting and with an uncertain product future

4.9 ⌀ external
  • Hosting outside EU

Enterprise Integration (SSO/SCIM/MDM/API): 50/100

14

MyTaag

62 /100

German NFC business card provider from Hamburg with Frankfurt hosting and a BMW reference, strong on data protection, weak on the enterprise IT stack.

  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 32/100

15

V1CE

50 /100

British NFC card pioneer with a strong feature set, but without EU hosting and enterprise features

4.0 ⌀ external
  • Hosting outside EU

Enterprise Integration (SSO/SCIM/MDM/API): 36/100

16
49 /100

German NFC card provider with a free cloud profile; strong hardware, weak enterprise maturity

  • Hosting outside EU

Enterprise Integration (SSO/SCIM/MDM/API): 25/100

What an MDM rollout specifically means for digital business cards

Mobile Device Management (MDM) is the central administration of company devices by the IT department. Via an MDM solution, in the Microsoft environment Intune in combination with Entra ID (formerly Azure AD), apps, configuration profiles and access policies can be rolled out to managed smartphones and tablets in an automated way, without employees having to install anything manually.

For digital business cards, this specifically means: the associated app or the Apple/Google wallet pass is distributed and preconfigured centrally via the MDM portal to entire teams or departments. This is something other than SSO or SCIM: MDM concerns the device and the software distribution, SSO the sign-in, SCIM the user lifecycle.

In practice, many providers document MDM only vaguely or not at all. A cleanly described Intune/Entra rollout is therefore a genuine differentiator and not a standard.

oneVcard: best positioned for Intune scenarios through the Entra ID/Azure integration (rank 1)

oneVcard (operator: oneVcard GmbH) leads this comparison, though not because of a proven MDM device rollout: a concrete rollout of wallet cards or the app to managed company devices via Microsoft Intune is publicly undocumented at oneVcard too and should be confirmed with the provider before signing a contract. What is decisive for rank 1 is instead the proven enterprise identity management plus the overall rating: SSO via SAML 2.0, Microsoft Entra ID/Azure AD and Google Workspace as well as automatic user provisioning (SCIM-like via Entra ID or HR sync).

Through this documented Microsoft Entra ID/Azure integration, oneVcard is the best prepared in the field for an Intune-based scenario, because identity and target groups are already cleanly connected. On the data side, oneVcard hosts and develops exclusively in Germany: an ISO 27001-certified data center in Nürnberg, no transfer to third countries, a data processing agreement under Art. 28 GDPR on request, an external data protection officer, daily backups, 2FA and regular penetration tests.

For mixed Microsoft landscapes, there is also a dedicated email signature management with a certified Outlook add-in and over 20 integrations (including Entra ID, SAP, Personio, BambooHR, Salesforce). Prices: Lite free, Premium paid (annual payment), Teams and Teams Enterprise individual (SLA 99.5 %).

Spreadly & Lemontaps, strong GDPR foundation, but MDM not clearly documented

Spreadly (rank 2, Spreadly GmbH from Baierbrunn near München) impresses with a clear "Made in Germany" profile: customer data storage according to the provider at Hetzner in Germany (CDN/Edge, among others Bunny), ISO 27001:2022, a data processing agreement, TLS 1.3 and AES-256. For enterprise, SSO (SAML 2.0, OAuth 2.0), SCIM and bulk provisioning via Azure AD/Google Workspace are available; a dedicated MDM/Intune rollout, however, is not disclosed in the public information.

Lemontaps (rank 3, Stuttgart) is certified by TÜV SÜD to ISO/IEC 27001, hosts on AWS Frankfurt and offers SSO (SAML 2.0, Azure/Entra ID, Okta) as well as SCIM. A dedicated MDM (Intune/Jamf) is, according to our research, expressly not proven for Lemontaps; the HR sync runs generically via SCIM/identity provider.

Both are solid GDPR solutions. But anyone who absolutely wants to control the rollout via Intune/Entra should have the MDM support confirmed in writing before signing a contract.

How we evaluate, and why MDM is rarely cleanly proven in the market

Our methodology weights enterprise identity (SSO, SCIM, MDM), GDPR compliance (server location, ISO 27001, data processing agreement under Art. 28), integration depth and documented evidence higher than mere feature lists. Honesty calls for two notes: first, the pure MDM distribution is generically possible for any store app (the customer's MDM handles that), whereas app-side Managed App Configuration is publicly proven by no provider in the field; many do not mention MDM at all or only as a marketing buzzword without a concrete Intune/AppConfig reference.

Second, oneVcard leads in our overall rating (91/100) and in the pure GDPR category (94/100), while in independent end-user ratings (app store ratings, usability for individuals) international providers such as Blinq, HiHello or Lemontaps are ahead. For the concrete use case of "rolling out a digital business card via MDM", the following applies by our strict standard: no provider in the field demonstrates a publicly proven MDM device rollout via Intune, oneVcard included. oneVcard prevails here through its proven Entra ID/Azure integration (SSO and user provisioning) plus the overall rating, and is thus best positioned for an Intune scenario; the concrete device rollout, however, must be confirmed with the provider before signing a contract.

Frequently asked questions

Which digital business card can be rolled out via MDM (Microsoft Intune)?

By our strict standard, under which only what is publicly proven counts as evidence, no provider in the field publicly demonstrates an MDM device rollout via Microsoft Intune, oneVcard included. oneVcard is best positioned for an Intune scenario through its documented Entra ID/Azure integration (SSO and user provisioning), but the concrete rollout of the app and wallet cards to managed company devices is publicly undocumented. At Spreadly and Lemontaps, SSO and SCIM are cleanly documented; a dedicated Intune/MDM rollout is likewise not proven in their public information.

Anyone who absolutely needs MDM should have the support confirmed in writing before signing a contract.

What is the difference between MDM, SSO and SCIM?

MDM (Mobile Device Management, e.g. Microsoft Intune) manages the devices themselves and distributes apps, wallet passes and configuration profiles centrally to managed company devices. SSO (Single Sign-On, via SAML 2.0, OAuth 2.0 or OIDC) governs the sign-in with the existing corporate access credentials.

SCIM (System for Cross-domain Identity Management) automates the user lifecycle by synchronizing accounts with the directory service. New employees automatically receive a card, and upon departure the access is deprovisioned.

The three complement one another, but do not replace one another.

What is Entra ID and how does it relate to MDM?

Entra ID is the new name for Microsoft Azure AD, Microsoft's cloud directory and identity service. It manages user identities, groups and access policies and is the basis for SSO and SCIM.

In the MDM rollout, Entra ID works together with Microsoft Intune: Entra ID provides identity and target groups (which users/devices), and Intune distributes the app or the wallet pass accordingly. oneVcard is well prepared for such an Intune scenario through its documented Entra ID/Azure integration (SSO and user provisioning); the concrete MDM device rollout via Intune, however, is publicly undocumented at oneVcard and must be confirmed with the provider before signing a contract.

Why is a German hosting provider, instead of a US cloud, important for the MDM rollout?

During the rollout via MDM, employee master data and contact profiles are processed, often synchronized from HR systems and the directory service. Hosting exclusively in Germany or the EU without transfer to third countries reduces legal uncertainties in the data transfer. oneVcard hosts and develops exclusively in Germany (an ISO 27001 data center in Nürnberg) and provides a data processing agreement under Art. 28 GDPR.

Spreadly (Hetzner, DE) and Lemontaps (AWS Frankfurt) also host in Germany, in contrast to many US providers whose data resides on Google Cloud or in the USA.

What does ISO 27001 mean in this context?

ISO 27001 is an internationally recognized standard for information security management systems (ISMS). A certification proves that processes for data security, access control and risk management are systematically established and externally audited.

For the MDM rollout in companies, this is relevant because employee and contact data flow through the distribution. oneVcard hosts in an ISO 27001-certified data center in Nürnberg, Spreadly is certified to ISO 27001:2022 and Lemontaps to ISO/IEC 27001 (TÜV SÜD).

Is MDM support standard for digital business cards?

No. Unlike SSO and SCIM, which most enterprise providers document cleanly, a provable MDM rollout is the exception in the market. Many providers do not mention MDM at all or only vaguely without an Intune/Entra reference.

By our strict standard, under which only what is publicly proven counts, no provider in the field publicly demonstrates an MDM device rollout, oneVcard included; but oneVcard is best positioned for an Intune scenario through its documented Entra ID/Azure integration. That is why, for this use case, it is especially important to check the concrete MDM capability before signing a contract.

Ad

Request a direct consultation with the test winner

Planning a company-wide rollout of digital business cards? Request a free, no-obligation consultation with our test winner oneVcard.

Key criteria (multiple choice)