Home

AD groups in update management (azure automation accounts)

%3CLINGO-SUB%20id%3D%22lingo-sub-816937%22%20slang%3D%22en-US%22%3EAD%20groups%20in%20update%20management%20(azure%20automation%20accounts)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-816937%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3Ei%20think%20i%20need%20help%20regarding%20the%20Azure%20automation%20acccounts%20update%20management.%3CBR%20%2F%3EOur%20goal%20is%20to%20centraly%20update%20our%20on-prem%20Windows%20servers.%3CBR%20%2F%3ETo%20achive%20this%20i%20installed%20the%20monitoring%20agent%20on%20a%20few%20test%20machines.%20(The%20machines%20appeared%20inside%20the%20update%20management%20already)%3CBR%20%2F%3ENow%20i%20want%20to%20create%20deployment%20schedules%20based%20on%20groups.%20(DCs%2C%20Fileserver%2C%20Database%20server%2C%20...)%3CBR%20%2F%3EIn%20the%20%22New%20update%20deployment%22%20blade%20i'm%20able%20to%20select%20%22Groups%20to%20update%22%20or%20%22Machines%20to%20update%22.%3CBR%20%2F%3EWhen%20using%20%22Groups%20to%20update%22%20i%20need%20to%20have%20groups%20based%20on%20queries.%3CBR%20%2F%3EWhen%20using%20%22Machiines%20to%20update%22%20i've%20seen%20that%20i%20can%20choose%20%22imported%20groups%20(AD%2FWSUS%2FSCCM)%22%20from%20the%20dropdown.%3CBR%20%2F%3EI%20enabled%20the%20Groupsync%20option%20in%20my%20log%20analytics%20workspace%20already%20(advanced%20settings%20%26gt%3B%20computer%20groups%20%26gt%3B%20Active%20Directory%20%26gt%3B%20Import%20..).%3C%2FP%3E%3CP%3EWhen%20looking%20back%20at%20the%20%22Machines%20to%20update%22%20blade%20i%20can%20only%20see%203%20groups%2C%20but%20not%20the%20groups%20i%20would%20like%20to%20use.%20(There%20are%20two%20custom%20groups%20visible%20and%20the%20%22domain%20computers%22%20group)%3CBR%20%2F%3EThe%20on-prem%20groups%20i%20would%20like%20to%20use%20are%20normal%20global%20security%20groups%20and%20the're%20synced%20via%20AADC.%3CBR%20%2F%3ESo%20at%20this%20moment%20i%20really%20don't%20know%20why%20my%20prefered%20groups%20are%20not%20visible.%3C%2FP%3E%3CP%3EAny%20help%20is%20highly%20appreciated.%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-816937%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAccounts%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAutomation%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EGroups%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EManagement%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EUpdate%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EUpdate%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-843324%22%20slang%3D%22en-US%22%3ERe%3A%20AD%20groups%20in%20update%20management%20(azure%20automation%20accounts)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-843324%22%20slang%3D%22en-US%22%3E%3CP%3EEven%20though%20there%20weren't%20any%20answers%3A%3C%2FP%3E%3CP%3EThings%20are%20working%20now.%20A%20few%20days%20later%2C%20i%20was%20able%20to%20see%20the%20groups%20supposed%20to%20be.%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20should%20to%20be%20fixed%20is%20the%20fact%2C%20that%20the%20feature%20%22usage%20of%20groups%22%20is%20not%20ideally%20implemented.%20After%20choosing%20a%20group%2C%20saving%20and%20reopen%20the%20config%20you%20can%20see%2C%20that%20the%20single%20machines%20were%20listet%2C%20no%20longer%20the%20group%20name%2C%20which%20results%20in%20the%20fact%2C%20that%20newly%20addede%20machines%20to%20a%20group%20woun't%20appear%20here.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Frequent Contributor

Hi,

i think i need help regarding the Azure automation acccounts update management.
Our goal is to centraly update our on-prem Windows servers.
To achive this i installed the monitoring agent on a few test machines. (The machines appeared inside the update management already)
Now i want to create deployment schedules based on groups. (DCs, Fileserver, Database server, ...)
In the "New update deployment" blade i'm able to select "Groups to update" or "Machines to update".
When using "Groups to update" i need to have groups based on queries.
When using "Machiines to update" i've seen that i can choose "imported groups (AD/WSUS/SCCM)" from the dropdown.
I enabled the Groupsync option in my log analytics workspace already (advanced settings > computer groups > Active Directory > Import ..).

When looking back at the "Machines to update" blade i can only see 3 groups, but not the groups i would like to use. (There are two custom groups visible and the "domain computers" group)
The on-prem groups i would like to use are normal global security groups and the're synced via AADC.
So at this moment i really don't know why my prefered groups are not visible.

Any help is highly appreciated. :)

1 Reply

Even though there weren't any answers:

Things are working now. A few days later, i was able to see the groups supposed to be. :)

 

What should to be fixed is the fact, that the feature "usage of groups" is not ideally implemented. After choosing a group, saving and reopen the config you can see, that the single machines were listet, no longer the group name, which results in the fact, that newly addede machines to a group woun't appear here.

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
30 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies