Hi Igor,
I found out why AD Import isn't pulling everything in after having my security guy check the machine account's object properties. Noticed that in my import rule under "Import
some computers on the
specified schedules", the following was set, below, where the computer in question hasn't been online for over 30 days now. Unless this is a default, I probably enabled this option awhile ago and had forgotten. With all the stale machine accounts in AD, not sure if it's a good idea to disable it or maybe increase the amount of days a bit so perhaps let me know what you think about my doing this. Thanks!
'Computer account password changed within the last 30 days.'
------------------------------
City & County of Honolulu: DIT
------------------------------
Original Message:
Sent: 10-05-2020 02:44 AM
From: Igor Perevozchikov
Subject: AD Import Anomaly
Hi Clint!
1. What version of NS you are using?
2. You can check these computers in database, try this query
select * from vRM_Computer_Item where Name like '%your pc name%'
---/// After AD import of computers, there should be Delta Update done on NS side to populate these computers in their OU in SMP Console.
3. Could you please show your AD Import rule settings which should import these computers from appropriate OU?
4. Could you please show how looks OU tree and computers there in your AD?
5. Is there errors/warning messages in NS log when you manually execute this AD Import rule? If yes, then please share logs output.
Thanks,
IP.
------------------------------
Software QA Engineer
Broadcom Inc.
Original Message:
Sent: 10-02-2020 08:09 PM
From: Clinton Watarai
Subject: AD Import Anomaly
Perhaps it's my misunderstanding of how the Microsoft Active Directory Import function is supposed to work but happened to come across a couple similarly named Win10 computers where I couldn't find one of them in All Computers. These are laptops and both are in same OU in AD where I have my AD import set to search this OU along with the main Computers one. Can anyone think of why one of these machines (even if the Altiris Agent wasn't on it) would not be in the database? I have my managed client purge set to remove after 1 month so if this did happen (e.g. this computer did have Altiris on it), wouldn't the AD import pull in the machine object into the database so it'll be shown as an unmanaged client?
------------------------------
City & County of Honolulu: DIT
------------------------------