GPO - Disable computer object that has not checked into network for 90 days.

Hi Experts,
The client we support  requested we create a GPO that disables computer objects that hasn't checked into domain for more than 90 days, something that we missed during the initial consideration for this was our workstation build engineers who build several machines and holds them in stock ready to be distributed when required, unfortunately when they send out machines to some of these has now surpassed the 90 days, and the results is the computer object is disabled, is there any way we can work around this, we cannot change the policy, but just ideas on a better process for the engineers building these machines, thoughts?
Craig PaulsenSystems EngineerAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

becraigCommented:
Simply group all your newly built workstations in their own OU and exclude that OU from the GPO.
0
Craig PaulsenSystems EngineerAuthor Commented:
thanks becraig, that's definitely an idea, then once the machine is ready to be deployed, the engineer just move the machine to the correct OU?
0
becraigCommented:
Yup So that way your current GPO to disable any computer objects not logged in will not apply.

However do remember the tombstone lifetime for AD objects:
you can verify this before you proceed:
To absolutely know, follow this procedure on your Windows 2008 domain controller:

1. Click Start, point to Administrative Tools, and then click ADSI Edit.
2. In ADSI Edit, right-click ADSI Edit, and then click Connect to.
3. For Connection Point, click Select a well known Naming Context, and then click Configuration.
4. If you want to connect to a different domain controller, for Computer, click Select or type a domain or server: (Server | Domain [:port]). Provide the server name or the domain name and Lightweight Directory Access Protocol (LDAP) port (389), and then click OK.
5. Double-click Configuration, CN=Configuration,DC=ForestRootDomainName, CN=Services, and CN=Windows NT.
6. Right-click CN=Directory Service, and then click Properties.
7. In the Attribute column, click tombstoneLifetime.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Get expert help—faster!

Need expert help—fast? Use the Help Bell for personalized assistance getting answers to your important questions.

JohnBusiness Consultant (Owner)Commented:
there any way we can work around this, we cannot change the policy,

Alternatively, consider this to be a business question and save yourself some work. Require engineers building machines to have a "bring forward" to start them every 75 days. I do not think this should be onerous or hard if the reason why is explained.

Otherwise they have to identify to you when to change groups. The second is more work for you and no easier than the first.
0
Craig PaulsenSystems EngineerAuthor Commented:
thanks,
0
JohnBusiness Consultant (Owner)Commented:
@craigleenz  - You are very welcome and I was happy to help.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Microsoft Legacy OS

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.