If I set a server to 'Limited Access' - 'Computer Access Only', does the /enroll URL still work? I'm assuming not, but it sure would be helpful. I'm trying to increase security by setting up a full access server in a restricted network, and changing our primary server to computers only, but all our documentation tells users to visit /enroll.... Todd
Limited Access
Best answer by mm2270
Hey @thoule
I was just informed earlier by our good friends at JAMF that I'm apparently completely wrong on this. The enroll page is available from a Limited Access JSS. For some reason at some point when we set up our Limited Access JSS back on version 8.x, the enroll page wasn't available from the outside. It supposedly should have been working, so I don't know what was happening there. Anyway, under version 9, its available. As well, the API is available on a Limited Access JSS too, which was definite news to me.
The only caveat is that in a true Limited Access JSS sitting in the DMZ, unless you also allow access to your internal LDAP servers, its likely users wouldn't be able to go through enrollment anyway if they are using their LDAP creds for authentication. In your case though, it should work since you were talking about having it be an internal server.
Also, take a look at this thread for more info, and optionally, reach out to Mike Paul @ JAMF, as he seems to be the one doing the most testing with optional setups and Limited access JSS.
https://jamfnation.jamfsoftware.com/featureRequest.html?id=2853
So anyway, ignore everything I said earlier. I was wrong, and frankly, I'm glad I was. The API bit was good news to my ears as I was never previously able to access it from outside.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
