search cancel

How to assign DLP endpoint agents to groups automatically by machine name

book

Article ID: 200674

calendar_today

Updated On:

Products

Data Loss Prevention Enforce Data Loss Prevention Endpoint Prevent

Issue/Introduction

You wish to automate the process of adding machines to endpoint agent groups based on all or part of their machine name as referenced in Active Directory

Environment

Release : 15.x, Windows Endpoints

Resolution

Here's an outline of how to get an an endpoint agent group assigned automatically by machine name.

 

1. Create the machine attribute in Agent Groups click the Manage Agent Attribute link:

 

2. Create a new attribute machine domain attribute and use the query from the example below

(&(objectCategory=Computer)(name=$AgentHostName$))


3. Next, create a new agent group, select the attribute you just created in the drop down. And enter a machine name with wildcard eg below.


Once selected, the drop-down will create a new text box.

In this example all machines names starting with 'WIN' will be included in the group

4. Save and assign a configuration setting to the group in the normal way

5. On your test agent, shutdown and restart the agent to force it to check in. Verify that it's assigned to the correct group

 

Attachments