Limited user permissions - policy log flushing

mkunesh
New Contributor III

I have an LDAP group added to my JSS for management. JSS Objects > Policies is set to Read, and JSS Actions > Flush Policy Logs is checked. However when I login as a user that is a member of this group, I cannot flush individual computer policy logs. I can Flush All for a given policy, but I cannot flush individual machines. However, if I set JSS Objects > Policies is set to Read & Update, I am able to flush individual machines. What is the expected outcome with this setting? I don't want this group to have the ability to edit policies, I do however want them to be able to flush individual machines who are scoped to the policy.

1 REPLY 1

mkunesh
New Contributor III

Forgot to mention I am running this on 9.12. This seemed to work as I configured it under 8.71.