Skip to main content

Want to create 2 policies-one for Mac and one for  Windows users.

Where All applications should be blocked from installation unless they're on a whitelist (using the publisher's information). However, users should still be able to change settings like Time, Region, and Network.

When a user requests an application that's not on the whitelist, an email shd be sent to our Helpdesk. And a technician will then approve or deny the request.

Hey San.

Always recommend keeping the two policies if using both Windows and Mac to keep them separated.

If you have ServiceNow, create and use the JIT option for specific location. like /Downloads.

If you do not have ServiceNow, you could possible configure JIT in PMC, and using the mailto in a message design and send email to your ITMS to create a ticket for request. I suggest that you use a webhook for the supported platforms if possible for notifications, as mail only works for Windows.
https://docs.beyondtrust.com/epm-wm/docs/bi-epm-messages#configure-message-email-settings-windows-only

Then default Low Flex for both Windows and Mac does not allow anything that is not approved, so add your time and date option to allow user access to those settings there.

 

Jens


Reply