Has anyone had to apply 2FA to their JSS authentication (presumably through a proxy because I do not believe the JSS supports it) to control access to the console? On a related note, is it possible to configure the JSS web console to run over a different port than client communication and has anyone done that?
We're potentially going to have to zone off our JSS to limit admin access to it, so I'm researching the impact of that. I'm also going to look into clustering and creating a read-only JSS if that's possible (so support staff can pull recovery keys without requiring them to 2FA into the zoned-off JSS, without letting anyone make policy changes from that JSS).
