The network gear I manage is only accessible via VPN, or from a trusted internal network...
...and by the gear I manage, I mean my home network (a router and a few managed switches and access points). If a doofus like me can set it up for my home, I'd think that actual companies would be able to figure it out, too.
If you have your own domain name+control over the DNS entries, a cute trick you can use for Jellyfin is to set up a fully qualified DNS entry to point to your local (private) IP address.
So, you can have jellyfin.example.com point to 192.168.0.100 or similar. Inaccessible to the outside world (assuming you have your servers set up securely, no port forwarding), but local devices can access.
This is useful if you want to play on e.g. Chromecast/Google TV dongle but don't want your traffic going over the Internet.
It's a silly trick to work around the fact that these devices don't always query the local DNS server (e.g., your router), so you need something fully qualified
but a private IP on a public DNS record works just fine!