Close to opening a support ticket, but thought I'd check to make sure this actually works for anyone before I do.
We've just recently setup SSO, which works well, provided I've pre-created the account under Settings->System Settings->Jamf Pro User Accounts & Groups. All seems to work as expected, rights work, etc. Accounts are hosted in our internal AD, I'm using "Add LDAP Account", all behaves the way I'd expect.
What I'm going for next, is trying to add AD Groups instead, and let departments manage who has access to the Jamf console without me being a bottle neck, manually setting up the users.
I've added an LDAP group with no issues, assigned permissions, assigned members in AD, but when any of those users attempt to log in, they get an error:
Access Denied. Contact your administrator to request access to the Jamf Pro server
Should this work? Without having to add each user manually?