2 ms·
Among many other duties, I help manage a fleet of ~80 Macs for number of early-stage tech companies. We're doing some things well, and some things we don't have
by anderiv 8y ago
Among many other duties, I help manage a fleet of ~80 Macs for number of early-stage tech companies. We're doing some things well, and some things we don't have a good answer for yet.
Good:
- Sophos Endpoint protection (cloud.sophos.com). We've found this to work great, is easily-configurable, and is inexpensive, something around $25/user/year for the "advanced" license, which also gets you DLP functionality.
- JAMF Pro for MDM. If starting now, I'd probably go with the hosted "JAMF Now" product. We use this to enforce security policy, deploy apps, monitor patch compliance, enforce patch installation, etc.
- NoMAD for Active Directory integration. I've just started R&D on deprecating our AD and moving to Okta as a primary identity provider, so once this is ready, I'll be switching over to JAMF Connect, which supports Okta.
Not good / In progress:
- Centralized log collection from the laptop fleet. This is challenging due to the on/off connectivity nature of laptops.
- Sometimes NoMAD messes things up and user passwords get out of sync between AD and the local MacOS user database. This causes no small amount of frustration as you can imagine.
Hopefully this is helpful. If anyone else has suggestions on the "not good" items, please reply!