Creating SCCM User and Device Collections based on Active Directory Groups

Create a User Collection and a Device Collection that pulls its members from an active directory group

1. Make sure you have Discovery set up on your Active Directory or Specific OU containing groups. You can do this by clicking Administration > Discover Methods then  right click on “Active Directory Group Discovery” and choose Properties. Click Add then configure appropriately.

2. From the Collection Properties window select “Membership Rules”

5-9-2014 3-04-08 PM

3. Select “Add Rule” then “Query Rule”

5-9-2014 3-09-58 PM

4. In the “Query Rule Properties” window Name your query rule and select “Edit Query Statement…”

5-9-2014 3-15-34 PM

5. In the “Query Statement Properties” Window select Criteria then the “Criterion Properties” Button (the star)

6. Choose Select
7. Make you’re query statement

User Collection based on Users in a specific group:
Criterion Value:  Simple
Attribute Class: User Resource
Attribute: Security Group Name
Operator:  is equal to
Value:    <Group Name> ex: Domain\AccountingUsers

Device Collection based on Devices in a specific group:
Criterion Value:  Simple
Attribute Class: System Resource
Attribute: System Group Name
Operator:  is equal to
Value:    <Group Name> ex: Domain\AccountingSystems

Leave a Reply

%d bloggers like this: