Please add the ability in discoveries to:
- exclude OU's
- exclude Virtual Cluster resource88 votes
Is this simply two checkboxes? You don’t need a list of OUs to exclude?
When creating custom discovery data using the smsresgen class there is no way to remove this from the discovery related tables in ConfigMgr. Since there is a supported way to add this data, there should be a supported way to remove it. This is necessary as a rollback option, to return ConfigMgr to its default state, before the custom discovery data was added.53 votes
When System Discovery finds an object that seems invalid, currently it won`t be imported (which is good).
ERROR: System <systemname> is a unsupported operating system, unsupported version, or malformed AD entry. Reported system type is: ().
However if the same object has an AD Group Membership and AD Group Discovery finds it, it won't check if it is valid, but write the DDR and create the object record in SCCM DB.
Please change AD Group Discovery so it validates new objects too.39 votes
SCCM is not synchronizing disabled accounts, so it is not synchronizing the change in the UserAccountControl-attribute, so from SCCM perspective every machine/user is active. This creates problems e.g. in Software Asset Management since collections can’t select AD active accounts only. SCCM should synchronize changed attributes or at least UserAccountControl of AD disabled accounts if the account exists in SCCM19 votes
Please add a check box which would enable me to have the DNS check skipped during computer system discovery. There are situations when a system may not resolve in DNS from the CM server, however I would still like to have the attribute data (LastLogon, pwdLastSet, etc) from Active Directory updated by the discovery process regardless of the DNS check. Currently these values are not updated if the system is not found.18 votes
The UBR registry key is responsible for displaying the subversion of a Windows 10 build to the end-user. For example 14393.*** where *** is the UBR string. If this is added to the HINV list of default classes this will allow for administrators to retrieve this information!
This is located in: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
This will help administrators differentiate what intermediate builds of Windows 10 they have install and also support patch management because they can easily compare the released patches to the subversion build each month.17 votes
AD Group discovery automatically discovers all computers and users that are members of the group (and nested groups). Sometimes it is not desired, as we choose what computers/users we want to discover via AD System/User Discovery. AD Group discovery should update group membership information for existing resources in the site. Or, ideally, provide an option to choose if we want to also discover group members, or not.16 votes
Allow the ability through Config Manager Client Settings to set Deferral of Upgrades (CB/CBB) for Windows 10 Clients
It would be ideal to be able to defer feature upgrades for Windows 10 via Client settings to avoid having to use a GPO. This would avoid the current dual scan issue with GPOs and WUfB Policy Settings.15 votes
Have the ability to include/exclude certain OU's from both Active Directory User and System Discovery.
E.G. I might have an "All Users and Groups" OU at the root domain level, which may contain sub OU's containing service accounts or mailbox accounts etc. that I don't want being picked up by discovery. The ability to pick which sub OU's to discover/not discover would be really handy in this scenario. The same applies for system/computer discovery also.14 votes
Software Inventory scan cycle (file scanning) of just Program Files can be ridiculously slow where it can run for over 12 hours or more which impacts all other inventory scan cycles. Worse still, if user powers down or restarts client the scan restarts from scratch. Disabling throttling is still too slow ( due to its use of WMI according to Tier 3) and not supported.
We would like a usable Software (file) Inventory scan cycle.12 votes
Add the option to filter out objects based on attributes.
where "Operating System Name" -notlike "%2003" and"Operating System Name" -notlike "%5.1" and -notlike "%OSX%"
where "Description" -notlike "%Physical%"
Where "OrganizationalUnit" -ne "OU=Disabled Objects,DC=contoso,DC=com"
it might delay the scan for each object and cause the discovery to take more time, but on the other hand make it more useful and stop discovering unwanted objects to the DB12 votes
Could you implement a reboot pending check in the console ?
this is not an easy way to implement reporting on it :
AD forest discovery fails and does not continue parse through the other forests after and "Discovery is being aborted due to an unexpected exception".
We would like to see where the discovery sees that it cannot contact or reach any given forest but is able to continue with the other forests to collect the data.10 votes
Please extend AD discovery to work with Multivalue Attributes.
For the moment, only the first value from the multivalued attribute is discovered.7 votes
We have many Discovery locations configured but we do not need discovery to run against them all on the same schedule. For example, we have many smaller domains where new objects are rarely created. We should be able to discover these environments less often than a workstations OU in our primary domain. The option to set both the Full and Delta discoveries would be ideal. This could extend to group and other discovery types as well.7 votes
Active Directory Group Discovery
As the title states it's a discovery method meaning it simply creates new resources (and/or updates values of attributes).
It never deletes groups that no longer exist in AD.
Wouldn't it be good to have a mechanism that keeps the SCCM in sync with AD (especially for groups and users)?
Thanks for taking this into consideration.6 votes
Detected as an unsupported operating system for the moment, in sytem discovery:
INFO: discovered object with ADsPath = 'LDAP://*.*.*/CN=W2016SRV,CN= SMS_AD_SYSTEM_DISCOVERY_AGENT
INFO: Property (operatingSystem) for (W2016SRV) was not set SMS_AD_SYSTEM_DISCOVERY_AGENT
INFO: Property (operatingSystemVersion) for (W2016SRV) was not set SMS_AD_SYSTEM_DISCOVERY_AGENT
ERROR: System W2016SRV is a unsupported operating system, unsupported version, or malformed AD entry. Reported system type is: (). SMS_AD_SYSTEM_DISCOVERY_AGENT
INFO: successfully completed directory search SMS_AD_SYSTEM_DISCOVERY_AGENT 10/14/2016 8:33:04 PM
Allow options we discover machines in AD in ConfigMgr without having to resolve them5 votes
For Windows 10 Credential Guard:
-Processor class lacks information if Virtualization is enabled
-Processor class lacks information if VT-x is enabled
-No information available if Secure Boot is enabled (I had to add a custom MOF (local|HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecureBoot\\State|UEFISecureBootEnabled)4 votes
It would be great if only supported OS:es are imported into ConfigMgr when using AD System Discovery, CM1702 agent will break some XP computers so why import the object into CM ? or perhaps add logics to filter system discovery from AD.4 votes
- Don't see your idea?