Hi folks,
We're testing Casper 9 while we maintain Casper 8 in production and have come across a puzzling discrepancy between the two when looking at setting up JSS accounts for folks whom we want to grant limited JSS access. I'm hoping we've just missed a checkbox somewhere, and/or someone has already encountered and resolved this.
In Casper 8, I can set up an account in the JSS for a user (JSS > Settings > Accounts) and simply check the "View Inventory Tab" box (listed under "JSS - Inventory Tab Privileges") to allow a user to login, click inventory and do searches and NOT view entire records. An equivalent item does not appear to exist in Casper 9 (JSS > Settings > JSS User Accounts and Groups), and the closest I can find is "Computers". Unfortunately choosing to allow "Read" for the "Computers" option allows the account to search for records and then also view their entire contents (including a system's installed Applications, uptime, DOP, etc), which is far more information than we want exposed by default.
It seems weird that the only way to allow an account the simple means to see if a record exists in the JSS is to let them view the entire contents of any record in the JSS.
I'm hoping there's a way in Casper 9 to replicate the limited access we have been able to grant users in Casper 8.
TIA for any insights!