What we’d like to do is to have a top-level policy filtered to all sites, which would force an LDAP group limitation for self-service apps whenever a technician chooses a specific category for that app.
The end result is that customers see all apps and their categories that aren’t limited, but when the technician logs into self-service on the customer’s Mac they then see the ‘hidden’ categories.
I do have this all working, save the automation of LDAP limitations for categories.
Any advice is appreciated!
