For those of you with the JSS on the DMZ, how are you handling the policies that fail if a machine is not on the network (and therefore not able to mount the internal servers).
We have about 200 subnets and about 50-60 buildings setup, but when a machine checks in from their home network, the JSS doesn't update with the unknown building, it leaves the last one it checked in with. This means I can't create a SG that says if "not in building, or building, or building, etc". And as we standup or shut down sites, I'm rarely notified (if ever, usually I stumble upon an IP range and then have to go ask someone if it's new or not) - so doing it by ip ranges doesn't seem feasible either.
Is my only other option to enable file shares on the DMZ? there's gotta be a better way.
