You're stuck between Cisco and your local management, eh?
Ask the Cisco folks how they would propose to deploy their AMP for Endpoints tool on macOS, then. Their deployment manual is rather silent on this topic.
Based on somebody else that's gone through this, and with some suggestions, it looks like either self-installations here, or use of an ISE.
Or tearing apart and rebuilding the Cisco packaging to meet your needs, if what's in chapter 3 of the deployment manual doesn't work with macOS. (The command-line description in Chapter 3 is not at all clear whether that's generic to all platforms, or if that's specific to Windows deployments.)
When next on the phone with Cisco support, I'd also (politely) ask for suggestions of alternate vendors that support direct deployments to the clients, too. And an update or three to their related documentation for macOS and Linux deployments.
As for somewhere else to rummage, see if somebody on the MacEnterprise mailing list or in its archives has encountered this case, too. (The archives search engine over there does work, though it's slow. I tried a search for Cisco AMP and Cisco endpoint and didn't turn up anything relevant, but I'd try a few other searches before joining and posting to the list.)