Interesting question here - What's the best way to scope to a dynamic group of computers not assigned to a site?
University setting. The global level is campus wide and each of our Colleges and/or major departments are grouped into different sites with their IT support contacts.
I would like to grab those computers not assigned to a site and scope an AD profile to them (yes still binding to AD - another discussion for another day) that gets a computer basic functionality (user login) while also notifying us that a computer is improperly configured (bad enrollment, errant site assignment, etc.).
I have groups for each site that contains all the members of that site, i.e. All College of Engineering Computers. Those work and are great containers to get this information.
I then have a group in the none scope set to do the same thing but exclude all these site specific groups. It's a bit process heavy doing it this way but overall accomplishes most of what I want.
However this group (and thus the policy scoped to it) tends to also pick up computers are they are "passing through", that is moving from one site to another.
For example, moving a computer from College of Business to School of Nursing will generate the following: a computer will drop out of College of Business and (expectedly) lose all configuration profiles, get roped into this group, generate an email and try to deploy the basic AD bind, then immediately drop out causing the basic AD bind to report a failure and be put in School of Nursing getting their appropriate profiles and AD bind.
That is causing a lot of failures in the profile log for this policies and a couple of computers left hanging out without any AD bind at all.
If you made it this far, congratulations. Any ideas/help would be appreciated.
I need some method to properly see computers not in a site with no change in that status for the past say hour or 2.
