Skip to content

Latest commit

 

History

History
77 lines (59 loc) · 4.23 KB

File metadata and controls

77 lines (59 loc) · 4.23 KB
title Add Computer to AD Group

Add group membership

Add a newly joined computer to Active Directory groups from a ConfigMgr Task Sequence. The self-contained Windows PowerShell 5.1 script checks direct membership, adds only when needed, and verifies the result on the same domain controller connection.

Current version: 1.0.0. This site follows main; the v1.0.0 release is a versioned snapshot with its own release notes.

Before deployment

Live ConfigMgr and Active Directory testing was not executed. Complete the environment-validation checklist before broad deployment.

Run as Local System in full Windows, after domain join and restart, inside an active ConfigMgr Task Sequence. WinPE, PowerShell 7, and ordinary interactive execution are not supported.

The default is Kerberos over LDAPS on TCP 636, with trusted domain controller certificates and a dedicated account delegated access only to the target groups. There is no automatic authentication or transport fallback.

Set the hidden custom variables ADGroupUserName and ADGroupPassword immediately before the packaged script step. Clear both on success and failure using native Task Sequence steps, and preserve the script's result. Never put credentials in parameters or package content.

Documentation

Guide Use it for
Deployment Prerequisites, parameters, credential cleanup, exit codes
Compatibility Candidate platforms and explicit opt-in modes
Security Least privilege, credential limitations, private reporting
Validation Automated checks and the environment-validation checklist
Architecture Discovery, membership verification, bounded retries
Logging Dedicated CMTrace log, sanitized diagnostics, smsts.log
Troubleshooting Readiness, certificates, permissions, failure handling
Examples Generic Task Sequence pattern and contributor setup
Release process Source-byte checksums and publication safeguards
Development Workstation setup, names versus paths, and shared banner generation
Distribution Release packages, standalone gist, licensing, and checksum verification

Outputs and results

Exit 0 means the computer is verified as a direct member of every requested group. Exit 1 means initialization or an operation failed. Successful additions are not rolled back when another group fails; verification does not prove replication to other domain controllers.

Source and releases

Browse source or read the script. Download release assets and their matching SHA-256 sidecars from GitHub Releases. Existing downloads do not update automatically.

For the standalone script, use the public gist snapshot with its MIT license and checksums. The repository remains authoritative; see distribution before using a separately downloaded script.

For changes, see contributing and the release process. Maintained by Claudio Mendes (@vartaxe), under the MIT license.

Related projects