In this tutorial, I will explain how to exclude OU from AD user discovery in SCCM. Starting in ConfigMgr version 2103, you can exclude organizational units from Active Directory User Discovery.
Recently, I was auditing the Configuration Manager setup for an organization. After the audit was completed, one of the requirements was to exclude user OUs from the discovery method.
This organization wanted to exclude HR and Finance Department users from being discovered in SCCM. Fortunately, the user accounts for these two departments were divided into separate organizational units. In addition, it was also requested to exclude the SCCM client installation on the laptops.
http://lyysfx.com/forum.php?mod=viewthread&tid=24948
http://lyysfx.com/forum.php?mod=viewthread&tid=18261
http://lyysfx.com/forum.php?mod=viewthread&tid=25505
https://carpentryforums.com/showthread.php?tid=10161
https://carpentryforums.com/showthread.php?tid=6331
https://qualityprogamer.de/forum/showthread.php?tid=54408
https://qualityprogamer.de/forum/showthread.php?tid=47956
https://biomedtalk.org/showthread.php?tid=16530
https://biomedtalk.org/showthread.php?tid=3052
https://amodsus.com/threads/vocazaj.518/
http://forofjcruiser.com/viewtopic.php?f=1&t=50215
http://forofjcruiser.com/viewtopic.php?f=1&t=44077
http://forofjcruiser.com/viewtopic.php?f=1&t=35532
http://airsoftvalcoisin.free.fr/forum/viewtopic.php?f=2&t=10914
http://airsoftvalcoisin.free.fr/forum/viewtopic.php?f=2&t=7446
http://airsoftvalcoisin.free.fr/forum/viewtopic.php?f=2&t=8564
http://airsoftvalcoisin.free.fr/forum/viewtopic.php?f=2&t=8596
https://www.cabrioletclub.com/forum/viewtopic.php?f=13&t=5471
https://www.cabrioletclub.com/forum/viewtopic.php?f=13&t=10849
https://www.cabrioletclub.com/forum/viewtopic.php?f=13&t=5193
https://www.cabrioletclub.com/forum/viewtopic.php?f=60&t=1510
If you are a ConfigMgr consultant, you may come across a similar requirement of excluding the discovery of users and certain devices from SCCM. Not to worry, it’s not a complex task and I will show you how to get this done.
Create Organization Units for Users
Organizational units (OUs) are container objects in Active Directory that allow you to organize and manage your network resources, including users, computers, and other objects.
By default, new Active Directory users are put in the Users container (CN=Users). Most organizations follow the best practices and create organizational units for users. For example, if you have users from various departments, such as IT, HR, Finance, Sales, and Support, it makes sense to create separate OUs for each department.
By organizing your users into OUs, you can simplify your management tasks. It also makes it easier to exclude the entire OU containing the users from discovery in SCCM.
Prerequisites
To exclude the organizational units from AD user discovery, the following prerequisites must be met:
- To exclude the OUs from user discovery, you must use an account that has full administrator permissions in SCCM.
- Before users can be excluded from user discovery in SCCM, the OUs must be created in Active Directory.
- The setup must be running Configuration Manager version 2103 or later.
- You must have configured Active Directory User Discovery in SCCM.
https://www.shufaii.com/thread-41918-1-1.html
https://www.shufaii.com/thread-41295-1-1.html
https://www.shufaii.com/thread-41443-1-1.html
https://www.shufaii.com/thread-38971-1-1.html
https://elforodelpoker.com/presentaciones/thesis-manet-t13464.html
https://elforodelpoker.com/presentaciones/good-resume-t14202.html
https://elforodelpoker.com/presentaciones/writing-employment-t14437.html
https://sportsreptile.site/thread-10268.html
https://sportsreptile.site/thread-10147.html
https://www.socalireefer.com/forum/showthread.php?tid=1401209
https://www.socalireefer.com/forum/showthread.php?tid=445825
https://www.2742bbs.com/forum.php?mod=viewthread&tid=1513
https://www.2742bbs.com/forum.php?mod=viewthread&tid=937
https://www.2742bbs.com/forum.php?mod=viewthread&tid=1451
https://www.2742bbs.com/forum.php?mod=viewthread&tid=1459
https://forum.survival-readiness.com/viewtopic.php?t=8006
https://forum.survival-readiness.com/viewtopic.php?t=7952
https://forum.survival-readiness.com/viewtopic.php?t=2187
https://forum.survival-readiness.com/viewtopic.php?t=7945
http://evtrucksforum.com/viewtopic.php?t=1999
http://evtrucksforum.com/viewtopic.php?t=53169
http://evtrucksforum.com/viewtopic.php?t=57487
http://evtrucksforum.com/viewtopic.php?p=345542
Exclude OU from AD User Discovery in SCCM
Follow the below steps to exclude organizational units (OU) from Active Directory User Discovery in SCCM:
Step 1: From the Configuration Manager console, go to Administration > Hierarchy Configuration > Discovery Methods.
Step 2: Right-click on Active Directory User Discovery and select Properties.
Comments
Post a Comment