Hi everyone!
IT manager here for a startup that has been around for a few years and they never really had any IT infrastructure till I showed up. We are looking at tightening security on our MacBooks (we already have JAMF installed on all of them) however we would like to review every single application installed on them.
I have come up with a list of 500 applications that I have been able to see via JAMF inventory. So my real question is, how the heck do I enforce what end users can and cannot install now? I know some have installed things like Steam and Battle.net which is not going to be allowed going forward.
Do I create a few policies in JAMf that remove them and then lock down installs via Firewall permissions?
Right now we are allowing our Engineers admin rights to machines but I foresee them just reinstalling Steam, etc...until I prevent it.
Thoughts? Suggestions?
Appreciate it.
