Most companies I’ve worked at where employees had a Microsoft work computers. They were under heavy control, even with admin privileges. I was wondering, for a corporate environment, how employees’Linux desktops could be kept under control in a similar way. What would be an open source or Linux based alternative to the following:
- policy control
 - Software Center with software allow lists
 - controlled OS updates
 - zscaler
 - software detection tool to detect what’s been installed and determine if any unallowed software is present
 - antivirus
 - VPN
 
I can think of a few things, like a company having it’s own software repos, or using an atomic distribution. There’s already open source VPN solutions if course. But for everything else I don’t really know what could be used or what setup we could have.


Sure. It’s certainly legal in NA and widely used. Any VPN can do that too. A corpo can install anything on their hardware and the hardware should be considered to be spying by default.
Oh and MITM proxying has been a fact of every corpo I’ve worked in. It’s the only way to reliably prevent people from accessing the list of sites the corpo doesn’t want accessed.