We have a group called "Jamf - User" that (until today) was set to Enrollment Only.
Then I discovered that users in that group could view (but not edit) computers. They can also view and edit users!
Specifically:
- For Computers, Create and Read are set
- For Users, Create, Read, and Update are set.
Is it not possible to allow users to self-enroll their Macs without also giving them access to view every computer and user in my JSS?