
Closed
Posted
Paid on delivery
I run a Linux-based instance of both nanoMDM and microMDM and I need a developer who can dive into their configuration layer to fine-tune software-deployment policies. My main goal is to enforce granular permissions management—who can install what, when, and under which conditions—across enrolled Apple devices without disrupting the existing enrollment workflow. You will be working directly on the Linux host, updating configuration files and, when necessary, adjusting the Go code behind nanoMDM/microMDM to expose the policy controls I need. Expect to handle token-based authentication, profile signing, and the overall packaging pipeline so that newly approved apps propagate automatically while anything outside the policy is silently blocked. Deliverables • Updated nanoMDM/microMDM configs (or patched source) reflecting the new permissions rules • A short, repeatable script or Ansible role to apply the changes on fresh servers • Verification report showing successful deployment and denial scenarios on at least two test devices Acceptance Criteria The final setup must push approved software with no manual touches, log any blocked attempts, and survive a full system reboot on Ubuntu 22.04 LTS. If you have recent experience bending nanoMDM or microMDM to your will—and you’re comfortable debugging on Linux—let’s get started.
Project ID: 40649258
22 proposals
Remote project
Active 3 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
22 freelancers are bidding on average ₹20,166 INR for this job

I am Mohd Sadab, and my team specializes in building production infrastructure that works, not just prototypes. We excel at implementing complex systems like binary distributions and policy enforcements that align perfectly with your project needs. Our experience with developing custom IoT hardware will enable us to provide effective solutions for your Linux-based instances of nanoMDM and microMDM. We have a strong grasp of token-based authentication, profile signing, and packaging pipelines – all essential for managing software deployments, which are crucial for your project. Our expertise covers debugging on Linux as well, so we can easily address any issues that might arise during the process. Moreover, our ability to deploy on AWS, GCP, and Azure aligns perfectly with the requirements of your Ubuntu 22.04 LTS environment. We understand how important it is for you to maintain a smooth enrollment workflow while ensuring granular permissions management between enrolled Apple devices. We guarantee a seamless experience by delivering short, repeatable scripts or Ansible roles to apply changes not just to existing servers but also on fresh ones. Overall, our end-to-end skills combined with our comprehension of your project's unique demands make us the perfect fit for this opportunity. Let's get started!
₹25,000 INR in 7 days
6.2
6.2

Hello, I am Vishruth from Banglore,India. Thank you for considering my proposal. I have carefully reviewed your project requirements and believe my 8+ years of real-world and freelance experience make me a suitable candidate for this project.
₹15,000 INR in 3 days
5.5
5.5

HI, KINDLY READ THROUGH MY PROPOSAL I will fine-tune your nanoMDM / microMDM setup on Linux to enforce granular software-deployment permissions across enrolled Apple devices controlling who can install what, when, and under which conditionswithout disrupting existing enrollment. MY APPROACH ✅ Review and update configuration files + Go source (where needed) for policy controls, token authentication, profile signing, and packaging pipeline ✅ Implement automatic push of approved apps and silent blocking of everything else ✅ Deliver repeatable deployment script/Ansible role and verify on test devices DELIVERABLES - Updated configs or patched source - Script / Ansible role for fresh Ubuntu 22.04 servers - Verification report (successful deploy + blocked attempts on ≥2 devices) QUESTIONS 1. Can you share current nanoMDM/microMDM version and access details (under NDA if needed)? 2. Any existing policy examples or specific permission rules already defined? Ready to start immediately.
₹25,000 INR in 4 days
5.3
5.3

With your Nano/Micro MDM Deployment Project, my expertise in Linux and the larger technology landscape place me in an excellent position to help you achieve your goals. I have a proven track record in delivering fine-tuned, granularly secure systems and pride myself on transforming complex requirements into clean, scalable solutions - a critical skill for reconfiguring your software-deployment policies. Furthermore, I'm well-versed in languages such as Python, PHP and JavaScript which proves handy when it comes to diving into Go code behind nanoMDM/microMDM for patching or making necessary adjustments to reflect new permission rules. My experience with token-based authentication, profile signing and packaging pipeline ensures that newly approved apps propagate automatically while blocking anything outside the policy; just what you require for your project. Finally, my methodology is rooted in producing long-lasting results, I will not just provide you with an updated configuration but a repeatable script/Ansible role that can be used on fresh servers effortlessly. I pledge to meet all your acceptance criteria, the final setup will push approved software with no manual touches ensuring to log any blocked attempts - so nothing escapes scrutiny. Let's collaborate for a reliable system that survives any reboot and benerate successful deployment for you.
₹12,500 INR in 5 days
5.0
5.0

Hi, I can customize your Linux-based nanoMDM/microMDM setup to enforce granular Apple device software-deployment policies without breaking the current enrollment workflow. The best solution is to first review your existing nanoMDM/microMDM configs, enrollment flow, token/auth setup, profile signing process, packaging pipeline, app approval rules, and current Ubuntu 22.04 deployment. Then I’ll update the configuration or patch the Go code where needed to support approved installs, blocked app handling, logging, and reboot-safe deployment behavior. I’m comfortable with Linux, Ubuntu, shell scripting, Ansible, Go code review/patching, MDM configuration, token-based authentication, profile signing, deployment automation, logging, and DevOps handover documentation. Deliverables will include: * Updated nanoMDM/microMDM configs * Policy rule implementation * Go patching if required * Approved app deployment flow * Blocked app logging * Token/auth handling review * Profile signing support * Repeatable shell/Ansible setup * Ubuntu 22.04 reboot validation * Test report for two devices * Deployment and denial verification I’ll focus on a stable, repeatable setup that pushes approved software automatically, blocks out-of-policy installs cleanly, logs the result, and remains maintainable for future servers. Best regards Ankit
₹12,500 INR in 2 days
3.6
3.6

Your requirement goes beyond basic MDM configuration because the critical part is enforcing policy decisions consistently without breaking the existing enrollment and deployment flow. The safest approach here is to isolate policy evaluation from the enrollment pipeline, then extend nanoMDM/microMDM only where the current configuration layer is insufficient. I can work directly on the Ubuntu 22.04 host to review the current nanoMDM/microMDM setup, identify where software-install permissions are currently evaluated, and implement granular controls for approved apps, installation conditions, and denial logging. If the existing configuration options are too limited, I can patch the Go layer to expose additional policy controls while keeping the deployment flow stable. The implementation would include: - configuration or source updates for policy enforcement - automated deployment/redeployment through a shell script or Ansible role - validation of token authentication, profile signing, and package propagation - reboot persistence testing - verification scenarios covering both approved and blocked installations on test devices I also prioritize observability during this type of work, so blocked attempts and policy decisions can be audited clearly instead of failing silently without traceability. Estimated delivery assumes access to the current environment, existing configs, and at least two enrolled Apple devices available for validation testing.
₹36,537.63 INR in 6 days
2.6
2.6

You need tighter software-deployment policies in nanoMDM/microMDM: approved apps should install automatically, unauthorized installs should be blocked and logged, while the existing Apple enrollment flow stays untouched. This is the kind of Linux-side debugging I handle. I’ve worked with server-side configuration, authentication flows, automation, and production deployment pipelines, including Python/Go-adjacent infrastructure and AWS/Linux environments at Marin Software. I can trace the policy path from configuration to MDM command execution, then patch the Go layer if the existing controls aren’t exposed. I’d focus on three things: granular allow/deny rules, reliable token/profile-signing and packaging flow, and repeatable deployment on Ubuntu 22.04. I’ll also verify both successful and denied scenarios across two test devices and make sure the setup survives reboot without manual intervention. Can you share the current nanoMDM/microMDM versions and how your app policies are defined today?
₹15,000 INR in 5 days
2.0
2.0

Customizing nanoMDM and microMDM deployment policies requires fine-tuning their configuration layers to enforce granular permissions management across enrolled Apple devices. I will build updated configuration files and patch the Go code to expose policy controls, handling token-based authentication and the packaging pipeline. I will deliver a short script to apply changes on fresh servers and a verification report showing successful deployment and denial scenarios. To confirm, will the Linux host be a standard Ubuntu environment or a customized setup. I will set up the necessary changes to meet the acceptance criteria. I propose we chat to lock in the exact scope and get started.
₹25,000 INR in 5 days
1.4
1.4

Hi-Bojan Here From Serbia. "IMPLEMENT GRANULAR MDM SOFTWARE DEPLOYMENT POLICIES" - "You want automated, policy-controlled application deployment across enrolled Apple devices." I can customize nanoMDM/microMDM configurations, authentication, profile signing, packaging, and Go components to enforce precise installation permissions and conditions. I will create repeatable Ansible automation, validate approved and blocked deployments across test devices, verify logging, and ensure the Ubuntu service survives reboot. Can you share your current nanoMDM/microMDM versions and configuration structure for an initial policy review? Looking forward to working with you.
₹15,000 INR in 5 days
1.4
1.4

Hi-Abrob Here From Uzbekistan. "IMPLEMENT GRANULAR MDM SOFTWARE DEPLOYMENT POLICIES" - "You want automated, policy-controlled application deployment across enrolled Apple devices." I can customize nanoMDM/microMDM configurations, authentication, profile signing, packaging, and Go components to enforce precise installation permissions and conditions. I will create repeatable Ansible automation, validate approved and blocked deployments across test devices, verify logging, and ensure the Ubuntu service survives reboot. Can you share your current nanoMDM/microMDM versions and configuration structure for an initial policy review? Looking forward to working with you.
₹25,000 INR in 7 days
1.0
1.0

I will customise your nanoMDM and microMDM deployment policies with a focus on reliable automated enforcement without disrupting the existing Apple device enrolment workflow. I can work across the Ubuntu host configuration layer and Go code where required to implement granular application permissions token authentication profile signing and automated deployment policies. The solution will include reusable configuration changes an Ansible role or deployment script and verification of both approved and blocked application scenarios across test devices. I will also ensure blocked attempts are logged and the setup remains persistent after reboot. My approach will be to first review your current nanoMDM and microMDM configuration then implement and test the policy layer incrementally. If you share your current configuration and the exact permission rules you want enforced I can start with an initial assessment. Thanks & Regards
₹21,402.78 INR in 5 days
0.0
0.0

The honest starting point: nanoMDM is deliberately minimal. It is a protocol relay, not a policy engine - it has no concept of "who can install what, when". So the permissions layer you want does not exist to be configured. It has to be built around it. The clean way is a policy service sitting in front of the command queue. Approved apps are evaluated against your rules before an InstallApplication command is ever enqueued, and anything outside policy is dropped and logged rather than sent and refused. That keeps your enrollment workflow untouched, which was your constraint. Patching the Go source is the alternative and I will do it if you prefer, but every upstream update then becomes a merge conflict. A service in front survives upgrades. Worth deciding before any code is written. 3 days for all three deliverables: the policy layer, an Ansible role that applies it to a fresh Ubuntu 22.04 host, and the verification report with allow and deny scenarios on two test devices, including a reboot to prove persistence. Two questions: how do you want identity resolved for the "who" in your rules - enrollment user, device group, or a serial allowlist? And are you signing profiles with your own Apple certificate already, or is that part of this?
₹12,500 INR in 3 days
0.0
0.0

YOU DON’T LIKE THE WORK, YOU DON’T PAY. I recently completed a similar project that involved fine-tuning deployment policies for microMDM, achieving impressive results. I am confident I can deliver the same quality for your project. Your focus on enforcing granular permissions management across enrolled Apple devices truly stands out. I can provide a solution that is highly responsive, integrated, scalable, and easy to use. While we might be new to Freelancer, we have over 5 years of experience off-site and I truly appreciate you taking your time to review our proposal and I would love to discuss this project more. We have multiple 5-star reviews on similar projects and rank in the top 1% among 75 million users! The worst that can happen is you walk away with a FREE consultation. Regards, TJ
₹18,750 INR in 7 days
0.0
0.0

I would review the current nanoMDM/microMDM configuration, enrollment flow, APNs/token handling, signing setup, and software packaging path before defining the policy boundary. The implementation would keep enrollment intact while introducing explicit allow/deny rules for approved software, condition-based deployment, auditable blocked attempts, and restart-safe service configuration on Ubuntu 22.04. Where configuration alone is insufficient, I would make focused Go changes with tests around policy evaluation and preserve upstream-compatible behavior where practical. I would also provide an idempotent Ansible role or shell script to apply the configuration and service changes consistently, plus a verification report covering approved deployment and denied scenarios on two enrolled test devices. Which Apple management channel is currently used for app deployment (MDM commands, Apps and Books, or a custom package workflow), and what conditions must policy decisions consider besides user/device identity?
₹12,500 INR in 3 days
0.0
0.0

If the policy files don’t lock down the profile signing chain, a rogue app could slip through the checks. I’ll add a verification step in the nanoMDM config that cross-checks each signed payload against an allowed-list before it’s pushed. I’ll also patch the Go code to load the rules from a JSON file, leaving the Ubuntu 22.04 LTS enrollment flow untouched. A common pitfall is assuming the log file survives a reboot; without persisting it in the system journal blocked attempts disappear. I’ll configure the service to write to /var/log/syslog and add a small health-check script that validates the policy on each start-up. Ready to start immediately and will have the first test run on your two devices within the first day.
₹25,000 INR in 4 days
0.0
0.0

Dear Hiring Team, I am writing to express my interest in configuring and fine-tuning your nanoMDM/microMDM deployment policies on Ubuntu 22.04 LTS. As a Senior IT Infrastructure & Systems Specialist with extensive experience in Linux administration, server configuration, and DevOps automation, I ensure stable, reproducible, and secure server environments. Execution Strategy & Technical Approach: ⚬ Policy & Source Refinement: Adjusting configuration files and patching underlying Go handlers where required to enforce granular software installation policies and silent blocking logic without breaking active MDM enrollment. ⚬ Security & Authentication: Verifying token authentication, payload signing, and pipeline propagation for target Apple devices. ⚬ Infrastructure as Code (IaC): Developing a clean Ansible role (or standalone Bash deployment script) to ensure all configurations, service dependencies, and firewall/token rules persist across server reboots. ⚬ Testing & Verification: Delivering an execution log verifying successful silent deployments and blocked attempt scenarios on test devices. I am ready to review your current host setup and start working directly on the environment. Sincerely, Fabián Stochyk Senior IT & Systems Specialist
₹25,000 INR in 3 days
0.0
0.0

Granular install permissions in nanoMDM and microMDM sit in the gap between the MDM protocol and your own policy layer, so I would implement the decision point as an authorisation shim in front of command enqueueing rather than trying to bend Apple's InstallApplication semantics. Concretely: extend the configuration layer for allow and deny rules keyed on enrolment attributes, patch the Go handlers where the policy hook needs to be exposed, keep token-based authentication and profile signing intact through the existing packaging pipeline, and log every blocked attempt with the rule that rejected it. Deliverables are the updated configs or patched source, an idempotent Ansible role that applies the whole setup on a fresh Ubuntu 22.04 host, and a verification report covering successful deployment and denial scenarios on two test devices plus survival of a full reboot. I work async with written progress notes and can start immediately.
₹17,100 INR in 8 days
0.0
0.0

RATIA, India
Payment method verified
Member since Nov 12, 2025
₹12500-37500 INR
₹1500-12500 INR
₹600-1500 INR
₹12500-37500 INR
$30-250 USD
$30-250 USD
₹1500-12500 INR
$30-45 USD
$250-750 USD
$250-750 USD
$250-750 USD
$10-30 USD
$15-25 USD / hour
$30-250 NZD
₹750-1250 INR / hour
₹400-750 INR / hour
$8-15 USD / hour
$25-50 USD / hour
$250-750 USD
$10-30 USD
$10000-20000 CAD
$10-30 USD
$30-250 USD