Welcome to Zentral
Zentral is a system to manage Apple devices under high security considerations. Zentral integrates deeply with enterprise architecture, such as IdPs, SIEMs and an entity’s PKI to implement robust security measures and best practices. Zentral fully supports config-as-code and its APIs can be managed with the Zentral Official Terraform Provider.
Zentral orchestrates Apple MDM and popular open source agents that complement it. Zentral integrations work with the agents as they are - if you are familiar with them, you can apply your knowledge.
Zentral offers Application Allowlisting with a user portal to handle authorization requests, based on user voting or admin approvals. Decisions are persistent because of stable identifiers and Zentral presents a full audit trail for permissions. Aggregates of Santa events expose shadow IT and guide building the Allowlist. Zentral's Munki integration gives you control and reporting over distribution & patching of software on the fleet. Zentral can run compliance checks against custom benchmarks. Compliance checks can be based on inventory data, scripts and queries. You can send compliance change events to other systems for conditional access via the Shared Signals Framework.How to run Zentral
There are many moving parts in the Zentral platform and not all are self-explanatory. If you want to get the most out of it, we recommend the Zentral SaaS offering or supported Zentral private cloud deployments for developer pairing and guidance. We offer managed instances for PoCs and are happy to help. For testing purposes (and for features not licensed under the ZPEL-1.0) you can use "docker compose".How to learn Zentral
- Read the Zentral docs and the Terraform provider docs
- Use the Terraform Starterkit as a primer for a macOS client in a repo
- Ask away in our channel #Zentral over at MacAdmins Slack
Key concepts in Zentral
Event-driven architecture
- Everything in Zentral is an event
- Events are presented with the same metadata structure and where possible, events are enriched with unified inventory data
- Events can be filtered and shipped to different stores
Tagging & sharding
Tags can be used to scope configuration to devices across all modules in Zentral. You can tag devices based on set conditions and attributes, you can use SCIM to create tags based on IdP group membership and you can also build mass tagging automations. You can use sharding to roll out configuration only to smaller subsets of machines. For example, you could use 20% shard on the tagcanary to test a new version of a software on only a sample of devices, before releasing it to the whole canary group.