Guys, anybody here done a sustainable software restriction for their environment?
I followed some tips here, from old threads, and it basically rotated around the concept of restricting the "installer" app. I understand that blocking software per title would have been the best course, but I just don't see it being sustainable as there could be non-mainstream software that we haven't heard of and they end up getting installed without resistance. To further, we just don't know how much we can restrict per tenant/account, please correct me if I am mistaken.
With restricting the "installer" app, I noticed that you can still install apps from Self Service without issues, provided that the said apps came from Jamf catalog or Apple store. If you upload a package and have a policy to install it, then add it on Self Service, the restrictions will kick in. This has been the challenge for us since we have software that are not in the built-in catalogs so we have to install them via policy: Sentinel One for example.