AD Group Discovery creating membership objects for security type groups RRS feed

  • Question

  • In SCCM 2007 AD Security Group Discovery, it's called "Include Nested Groups" which if you don't check that box, only the security group objects are discovered and none of the nested group memberships (User or computer objects) are created...plus it didn't matter whether it was a Security type or a Distribution type security group...it simply didn't create the membership objects. In SCCM 2012 AD Group Discovery, the setting is called "Discover the membership of distribution groups" but even when you don't check that box, AD Group Discovery still creates user and computer objects for the nested members of security type groups. I am still hoping I just missed something and I can still prevent AD Group Discovery from creating membership objects in security type groups.  

    • Edited by scarneol Monday, October 22, 2012 8:47 PM
    Monday, October 22, 2012 8:46 PM


  • Hi,
    As far I know you cannot deselect "nested members", The setting you are refering to "Discover the membership of distribution groups" are used to discover members in "distribution groups" in ad and not security groups.


    -- My System Center blog ccmexec.com -- Twitter @ccmexec

    • Proposed as answer by Garth JonesMVP Wednesday, February 4, 2015 1:19 PM
    • Marked as answer by Garth JonesMVP Saturday, October 10, 2015 2:49 PM
    Wednesday, November 7, 2012 10:05 AM