I just want the devices to stay secure and compliant, and also keep our SOC2 people happy. At previous work, I evaluated many anti-virus for Mac, installed CarbonBlack to 100+ people. All it found was a Windows virus on a Mac on a plugged hard drive over 2 years. Not dismissing, but our company got acquired, we deprecated it, we saw 2 more anti-virus which was only problems. I don't want to just check a checkbox.
So far, the closest I feel is Kolide of easier visibility & Slack based remediation (bugging people works), looked at Jamf Now and SimpleMDM. You can safely uninstall any MDM too, so I don't see what the point is unless the device is locked and encrypted. Don't want to be dismissive, just looking to hear ideas!
Windows E3 & E5 licenses on cheap windows devices, yes please. Labor costs are minimal comparatively. Rollout is cheap and easy and you tick all the boxes for Government compliance no sweat.