I have a 2012 SCCM environment in our network.
We run the following discovery methods.
AD Forest, AD Group, AD System, AD User, Heartbeat Discovery.
When looking at Users within SCCM it is picking up Users from trust domains or other domains within the forest.
For example I am based in the UK, I manage our SCCM 2012 environment and AD for UK.CompanyName.com, which is a child domain of CompanyName.com.
When I check adisrdis.log it is discovering Users from other domains, but the discovery settings are only set to LDAP OU=Domain Users,DC=uk,DC=CompanyName,DC=com.
I think it is discovering these users from other domains because they are in AD groups from our Domain, and the box is ticked to
"Discover objects within Active Directory Groups"
(Screenshot attached)
Is there a way of excluding other domains?
Thanks Matthew