Solved

How to make new computers a member of a specific AD computer group automatically...by GPO maybe?

Posted on 2006-10-31
4
208 Views
Last Modified: 2010-03-18
Hi,
I would like to make any new computer accounts added to a specific organizational unit a member of a specific AD computer group.  For example...if my technicians join a new computer to the domain, and then move the computer account to a particular departmental OU, I would like the computer account to be automatically enterred into the appropriate AD computer group.  I had thought that there would probably be a setting in group policy that would do this for me but can't seem to find one off hand.  Any thoughts on how to do this?  
Thank you in advance for your help.

Tidbits about the network:  workstations are W2k Pro and WinXP Pro...AD is server 2003

0
Comment
Question by:AFAIT
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 9

Expert Comment

by:SamuraiCrow
ID: 17845629
You can do this with the netdom command.  The basic syntax looks like:

NETDOM JOIN <computer>/Domain:<domain> [/OU:<ou path>] [/UserD:<user>]

You could add this to a small batch file and have it prompt for passwords when it kicks off.  Read the following link for more details:
http://support.microsoft.com/kb/266651

Let me know if you would like assistance with the syntax
Crow

0
 
LVL 38

Accepted Solution

by:
Shift-3 earned 500 total points
ID: 17851954
You could set up a scheduled task to periodically run the vbscript below.

Save the text below the line in a file with a .vbs extension.  Customize the strComputerOU variable with the Distinguished Name of the OU the computers are in.  Customize the strTargetGroup variable with the Distinguished Name of the group you want to add the computers to.

I borrowed the code from these Microsoft articles:
http://www.microsoft.com/technet/scriptcenter/resources/qanda/sept04/hey0902.mspx
http://www.microsoft.com/technet/scriptcenter/resources/qanda/jan06/hey0123.mspx

____________________

On Error Resume Next

'Distinguished Name of the OU the computers are in
strComputerOU = "ou=Sales Department,dc=mydomain,dc=local"

'Distinguished Name of the group to add the computers to
strTargetGroup = "cn=Sales Group,cn=Users,dc=mydomain,dc=local"

Set colItems = GetObject _
    ("LDAP://" & strComputerOU)

For Each objItem in colItems
    If objItem.Class = "computer" Then
      Set objGroup = GetObject ("LDAP://" & strTargetGroup)
    objGroup.Add(objItem.ADsPath)
    End If
Next
0
 

Author Comment

by:AFAIT
ID: 17857332
I am not so sure that I want my Helpdesk staff to be using the NETDOM command to join computers to the domain.  Regarding the vbscript...that might work...I will give it a shot and report back.  I was really hoping there would be a better way other than a script though...

I do thank you both for the feedback and let you know the result.  (I also need to take some time to read all three of the articles posted).
Thank you again.
0
 

Author Comment

by:AFAIT
ID: 17857502
Hey Shift-3,

That script worked fantastic!  I will use that.  Thank you both very much for your help.
...awarding points...
0

Featured Post

Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
IPv6 Implementation - Cisco ASA5512 and Windows DHCPv6 1 72
SQL Server Communications Audit 5 126
Password managers 1 65
Surface Pro 4 wifi 4 50
Greetings, Experts! First let me state that this website is top notch. I thoroughly enjoy the community that is shared here; those seeking help and those willing to sacrifice their time to help. It is fantastic. I am writing this article at th…
Enterprise networks where VoIP phones have been deployed frequently use port configurations that allow both a computer and an IP phone to be plugged into the same switch port but use different VLANs. On Cisco equipment I'm referring to the "native V…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question