For Linux (Debian)

Secure & remotely support Linux desktops & servers from one dashboard

Protect the Linux machines you're responsible for — desktops and headless servers alike — with default-deny application control, USB device lockdown, comprehensive IT audit mode, and encrypted remote troubleshooting. All from the same secure dashboard you use for Android and Windows.

Works on Debian-based Linux systems — desktops and headless servers. Focuses on security, audit, and remote support.

Default-deny application control

SentinelMDM uses fapolicyd — a kernel-level execute-allowlisting daemon — to block anything not explicitly approved from running on your Linux desktops and servers:

  • Package-managed software is automatically trusted — everything installed via apt/dpkg is allowed without manual configuration.
  • Custom-installed binaries are approved individually — anything outside the package manager requires explicit allowlisting, just like Windows AppLocker.
  • Audit and enforce modes — test in audit-only (logs would-be denials without blocking) before switching to full enforcement.
  • Tamper-resistant — the daemon runs at the kernel level via fanotify, so even root cannot bypass the policy without explicit dashboard approval.

Linux toolkit

Security & audit, all in one place

Application control

Default-deny execute-allowlisting via fapolicyd — blocks unapproved software from running, even under root.

USB device lockdown

Kernel-level USB device authorization via USBGuard — block unauthorized peripherals while keeping keyboards and mice safe.

Screen-text capture with AI

On-screen text capture on Linux desktops, analyzed by AI so notable content and activity stand out at a glance.

IT audit mode

Collect system forensics across 18 categories — processes, services, tasks, autoruns, network, users, software, and more.

Network threat detection

ARP sweep detection, canary IP monitoring, and dark-space hit alerts flag spoofing or reconnaissance on the local network.

Secure remote troubleshooting

Connect to a desktop or headless server over an encrypted SSH tunnel — dormant until needed, fully logged for accountability.

REALITY stealth transport

Agent-to-server connections are obfuscated to look like standard TLS traffic, bypassing DPI and network censorship.

Encrypted by design

All agent traffic is end-to-end encrypted over a secure tunnel and stored encrypted at rest — your data never sits in plaintext.

Lightweight daemon

Runs as a systemd service from boot with minimal resource usage — designed for both desktops and headless servers.

One dashboard, all platforms

Manage Android phones, Windows PCs, and Linux desktops/servers side by side — no second console, no extra subscription.

Common questions

Linux FAQ

What can SentinelMDM do on a Linux system?

On Linux, SentinelMDM provides security and remote support for both desktops and headless servers (Debian-based): default-deny application control that blocks unapproved executables, USB device lockdown that authorizes or deauthorizes peripherals at the kernel level, comprehensive IT audit mode with 18 collection categories, local network threat detection with ARP sweep and canary IP monitoring, and end-to-end encrypted remote troubleshooting. It runs as a lightweight systemd daemon.

How does Linux application control work?

SentinelMDM uses fapolicyd, a kernel-level execute-allowlisting daemon. The distro's package database (everything installed via apt/dpkg) is automatically trusted. Anything installed outside the package manager requires explicit allowlisting. In audit mode, denials are logged without blocking; in enforce mode, unapproved executables are blocked from running — even under root.

Can I lock down USB devices on Linux?

Yes. SentinelMDM uses USBGuard to authorize or deauthorize USB devices at the kernel level. In enforce mode, only devices with an explicit allow rule are usable — anything newly plugged in is blocked immediately. An input-device safety net ensures keyboards and mice can never be accidentally locked out.

What is IT Audit Mode?

IT Audit Mode collects system forensics across 18 categories: processes, services, drivers, scheduled tasks, autoruns, network connections, users, installed software, security state, hosts file, file signing, WMI persistence, browser extensions, and system events. It produces structured JSON output suitable for compliance reporting, incident response, or routine health checks.

How much does it cost?

Linux desktops and servers count as devices on your SentinelMDM plan. Pricing starts at $3/device/month (Android, Windows, or Linux, mixed freely). Every plan includes a 30-day free trial. See full pricing →

Secure your Linux machines

Start a 30-day free trial, or explore the dashboard first with a free demo account. Managing Android or Windows too? It's all in the same place.