Protect the Linux machines you're responsible for — desktops and headless servers alike — with default-deny application control, USB device lockdown, comprehensive IT audit mode, and encrypted remote troubleshooting. All from the same secure dashboard you use for Android and Windows.
Works on Debian-based Linux systems — desktops and headless servers. Focuses on security, audit, and remote support.
SentinelMDM uses fapolicyd — a kernel-level execute-allowlisting daemon — to block anything not explicitly approved from running on your Linux desktops and servers:
Linux toolkit
Default-deny execute-allowlisting via fapolicyd — blocks unapproved software from running, even under root.
Kernel-level USB device authorization via USBGuard — block unauthorized peripherals while keeping keyboards and mice safe.
On-screen text capture on Linux desktops, analyzed by AI so notable content and activity stand out at a glance.
Collect system forensics across 18 categories — processes, services, tasks, autoruns, network, users, software, and more.
ARP sweep detection, canary IP monitoring, and dark-space hit alerts flag spoofing or reconnaissance on the local network.
Connect to a desktop or headless server over an encrypted SSH tunnel — dormant until needed, fully logged for accountability.
Agent-to-server connections are obfuscated to look like standard TLS traffic, bypassing DPI and network censorship.
All agent traffic is end-to-end encrypted over a secure tunnel and stored encrypted at rest — your data never sits in plaintext.
Runs as a systemd service from boot with minimal resource usage — designed for both desktops and headless servers.
Manage Android phones, Windows PCs, and Linux desktops/servers side by side — no second console, no extra subscription.
Common questions
On Linux, SentinelMDM provides security and remote support for both desktops and headless servers (Debian-based): default-deny application control that blocks unapproved executables, USB device lockdown that authorizes or deauthorizes peripherals at the kernel level, comprehensive IT audit mode with 18 collection categories, local network threat detection with ARP sweep and canary IP monitoring, and end-to-end encrypted remote troubleshooting. It runs as a lightweight systemd daemon.
SentinelMDM uses fapolicyd, a kernel-level execute-allowlisting daemon. The distro's package database (everything installed via apt/dpkg) is automatically trusted. Anything installed outside the package manager requires explicit allowlisting. In audit mode, denials are logged without blocking; in enforce mode, unapproved executables are blocked from running — even under root.
Yes. SentinelMDM uses USBGuard to authorize or deauthorize USB devices at the kernel level. In enforce mode, only devices with an explicit allow rule are usable — anything newly plugged in is blocked immediately. An input-device safety net ensures keyboards and mice can never be accidentally locked out.
IT Audit Mode collects system forensics across 18 categories: processes, services, drivers, scheduled tasks, autoruns, network connections, users, installed software, security state, hosts file, file signing, WMI persistence, browser extensions, and system events. It produces structured JSON output suitable for compliance reporting, incident response, or routine health checks.
Linux desktops and servers count as devices on your SentinelMDM plan. Pricing starts at $3/device/month (Android, Windows, or Linux, mixed freely). Every plan includes a 30-day free trial. See full pricing →
Start a 30-day free trial, or explore the dashboard first with a free demo account. Managing Android or Windows too? It's all in the same place.