Allow for the import of Active Directory groups as LDAP Smart Labels.
This would easily allow for granular label management for users and devices - especially if the groups have already been set up in AD. Additionally, this could potentially allow for some cross over and AD management via KACE and vice versa - as users and computers could be managed via AD in relation to their group membership and therefore their label association.
It would be nice if we could import AD groups to have them available as labels so we would not have to create each one manually. Especially since the appliance is already capable reading / pulling useful AD info in the appliance.
Ben Schwartz commented
This already works. I can create a user label based on security group. I can create device labels based on computer OU. Device LDAP label test produces zero results, but does apply only on next computer inventory, try it out:
Device LDAP label:
Base DN: OU=Stage,OU=Workstations,OU=Company,DC=company,DC=com
Search filter: (CN=KBOX_COMPUTER_NAME)
User LDAP label:
Removed mine but basically the same you just need to use a different variable.
Page 14 - https://docs.google.com/file/d/0BxH6X8H1Q3CRYmZpNmZOZUFaOVU/edit?pli=1