Endpoint Protection

 View Only
  • 1.  Avoid AD assignement groups

    Posted Apr 08, 2014 12:27 PM

    Hi all,

    I received an inherited console with groups created by importing OU from active directory. I need to migrate clients from SEP11 to this new console and I need to avoid the assignement to the AD groups and send the clients directly to the ones that are created by myself. I created an installation package exporting the policies of this group, but when I install SEP12, the clients goes directly to the OU and no to the group that I want.

    Is there any chance to avoid these and send the client directly to the group that I want?

    Thanks in advance



  • 2.  RE: Avoid AD assignement groups

    Posted Apr 08, 2014 12:29 PM

    You need to break AD sync

    Just follow the reverse to break here:

    http://www.symantec.com/docs/TECH96201

    You can delete the group (OU) and create a new one and don't sync it:

    http://www.symantec.com/docs/TECH95924

    Once broken, clients will go to the default group and you can move to whatever group (OU) you want :)



  • 3.  RE: Avoid AD assignement groups

    Posted Apr 08, 2014 12:32 PM

    if AD is imported to SEPM, then all the clients report to that particular OU only. If you want then to report to your new group, then you need to remove OU.. there is no other way



  • 4.  RE: Avoid AD assignement groups

    Posted Apr 08, 2014 01:09 PM

    Ok, the sync option is unmarked. So when I'll delete the OU all the clients will go to the default group? What happends if I create a group and then I import AD inside this one? Can I move clients too?

     

    Thanks for the quick response



  • 5.  RE: Avoid AD assignement groups
    Best Answer

    Posted Apr 08, 2014 01:13 PM

    Correct, delete the OU and they call will go to the default group upon checking back in.

    You cannot move clients inside an AD synched group. You would need to move in AD first and SEPM will sync with your AD and then the client will move.

    I'm not a fan of AD sync as you're a bit limited in moving clients around.