I'm trying to tighten security in our organization and would like to control what applications can be launched.
Right now my biggest issue is someone bringing an app in on a USB drive and launching it or dragging it their desktop and launching it from there. I want them to still be able to use USB drives but I want to control what apps can launch system wide.
I have a test configuration profile setup with restrictions enabled. I can add each and every app that I want to allow to run but that seems tedious. I can only allow apps in the Applications folder to run but that doesn't help with the USB issue.
Anyone doing something similar or have a better way to do this ?
Thanks in advance.