Can I conditionally add a computer object based on name field contents?

Daniel Kennedy 41 Reputation points
2021-09-28T19:34:00.047+00:00

Hello,

Wish to know if it is possible to condition the addition of a computer object if it meets a rule based in name field content typed.

e.g. Computer object would be added to AD only if user trying to create it has typed a name that starts with "SYM-".

The goal is to force nomenclature usage adding computer objects into an OU.

Thank you in advance for your inputs.

Best regards,

DK

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,898 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Jai Verma 461 Reputation points
    2021-09-28T19:40:12.42+00:00

    Domain Join process has not check or cannot be forced to check the name. However, it is a very common requirements in organisations. Mostly, organisations have in-house desktop/laptop and server build team, who build client and server and as a process follow a naming format.

    1 person found this answer helpful.
    0 comments No comments

  2. Daniel Kennedy 41 Reputation points
    2021-09-28T20:19:54.267+00:00

    Thank you. Agree, but I´m looking about AD internal possibilities . Best regards, DK

    0 comments No comments

  3. Limitless Technology 39,371 Reputation points
    2021-09-30T14:12:14.813+00:00

    Hello,

    In my experience there is no way to from AD to handle it

    If you are not placing the computers into your domain your self, then can I assume that the owners of those machines have administrative privileges? If so, they can change the name of their machines to make them compliant with your network requirements. You need to send out a policy/procedure letter informing all of these requirements that must be met. Failure to comply will have consequences; such as, those devices not in compliance will have computer and user accounts disabled until such as to have said devices placed in compliance with your networking policy/procedure.

    On other note, you can schedule a Task scheduler which will get list of all AD computer accounts daily and sent you via email then you can verify those name and have rename it.


    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments