We're using JSS version 8.61, bound to AD.
We have an odd problem with Casper Remote Screen Sharing. Accounts individually added to the JSS (either local or AD) and given permission to "Use Casper Remote" and to "Screen Share with Remote Computers" can successfully screen share with Casper Remote.
However, most of the accounts we use to authenticate to the JSS are allowed via membership in an AD group. For the most part, this works fine, but these accounts cannot successfully screen share using Casper Remote. They can use other Casper Remote features successfully (executing a policy on a remote machine, for example) but when screen sharing is attempted, the process fails right at the end with a 'Permission denied for example_user_123' error in the /var/log/jamf.log on the target, and 'Permission denied to share screen' shown in Casper Remote.
In Casper Remote, in the 'Status' field, the connecting user sees "Authenticating..., Opening ssh connection, Verifying..., Starting screen sharing", but then gets 'Permission denied to share screen' right at the end. To reiterate, the AD group they are a member of has permission to "Use Casper Remote" and to "Screen Share with Remote Computers", and the same user, when removed from that AD group but added to the JSS as an individual LDAP user with those checkboxes ticked, can connect successfully.
Is this a known issue?
Thanks,
Robin
