Prevent users with admin rights from removing the Fleet agent #25711
Labels
customer-mozartia
customer-preston
:product
Product Design department (shows up on 🦢 Drafting board)
Gong snippet: https://us-65885.app.gong.io/call?id=6719433018862554186&highlights=%5B%7B%22type%22%3A%22SHARE%22%2C%22from%22%3A94%2C%22to%22%3A644%7D%5D
Problem
All employees at
customer-mozartia
have admin permissions to their computers. This means they can remove the Fleet agent from their computers.What have you tried?
customer-mozartia
does enroll most of their macOS hosts via ADE, so they have the option to make the MDM profile non-removable. Doing this does not cover Windows or Linux enrollments, however.We talked about methods to incentive employees to keep hosts enrolled, like requiring enrollment to get access to the corporate network. This would not currently work with their internal policies.
Potential solutions
customer-mozartia
would like to have a mechanism to prevent admin users from removing the Fleet agent from their computers.What is the expected workflow as a result of your proposal?
A user with admin privileges attempts to remove the Fleet agent from their host > they are not able to because there are mechanisms in place that prevent that.
The text was updated successfully, but these errors were encountered: