Integrate Google’s Santa project into SimpleMDM?
The clue is in the name SimpleMDM - your product makes the difficult parts of managing your Mac devices simple - setting up and managing Munki could be challenging, and now the easy to use implementation you’ve provided is a great fit for lots of organisations.
Can you apply the same magic to Google Santa please?
https://github.com/google/santa
Here’s the use case. In our organisation, end users run with administrator access. This empowers them to do all the things they need to do to be productive, and ensures IT isn't a bottleneck…
…but - with great power comes great responsibility. There’s malware out there, or at least “potentially unwanted applications” that we’d rather not have running in our environment. And worse (?) there are software licencing hurdles - tools like Docker which are free for personal use, but can’t be used in enterprise without a licence.
Having an easy to use Santa framework to easily block applications like these would make a huge difference to us… as the alternative is yanking admin rights, a LOT of tickets and a lot of time packaging software via autopkg and magic to deliver it via Munki instead….
So make my (Christmas*) wish come true…? </Mariah Carey>
*not a suggested implementation timeline
-
squirke commented
Whilst Santa can be used with a sync server to do lots of clever things, I think for a lot of organisations, just the ability to be able to create and manage an app deny-list via configuration profiles would be a huge step forward.
With that in mind, could you consider adding the North Pole Sec application Santa to your shared app catalogue… as WELL as configurations to pre-approve the system extension and background process.
In addition (and yes, I don’t ask for much!) if SimpleMDM can also provide a UI to allow admins to easily create their Santa denylists, that would be huge. Looking at the existing UI, you already have an example (the system extensions UI) that could be easily modified to let admins add apps to a deny list, without having to become a Santa expert.
I've included a screenshot, showing why I can't be trusted with anything to do with UI design... (but as an example of how this could potentially work...)