Import NT domains into an existing group

Prev Next

Import systems from an NT domain into a group you created manually.

You can populate groups automatically by synchronizing entire NT domains with specified groups. This approach is an easy way to add all systems in your network to the System Tree at once as a flat list with no system description.

If the domain is large, you can create subgroups to assist with policy management or organization. To do this, first import the domain into a group of your System Tree, then manually create logical subgroups.

Tip

To manage the same policies across several domains, import each of the domains into a subgroup under the same group. The subgroups will inherit the policies set for the top-level group.

When using this method:

  • Set up IP address or tag sorting criteria on subgroups to automatically sort the imported systems.

  • Schedule a recurring NT Domain/Active Directory synchronization server task for easy maintenance.

For details about product features, usage, and best practices, click ? or Help.

  1. Select MenuSystemsSystem TreeGroup Details and select or create a group in the System Tree.

  2. Next to Synchronization type, click Edit. The Synchronization Settings page for the selected group appears.

  3. Next to Synchronization type, select NT Domain. The domain synchronization settings appear.

  4. Next to Systems that exist elsewhere in the System Tree, select what to do with systems that exist in another group of the System Tree.

    Tip

    Best practice: Don't select Add systems to the synchronized group and leave them in their current System Tree location, especially if you are using the NT domain synchronization only as a starting point for security management.

  5. Next to Domain, click Browse and select the NT domain to map to this group, then click OK. Alternatively, you can type the name of the domain directly in the text box.

    When typing the domain name, do not use the fully-qualified domain name.

  6. Select whether to deploy the Trellix Agent automatically to new systems. If you do so, configure the deployment settings.

    Tip

    Best practice: Because of its size, do not deploy the Trellix Agent during the initial import if the container is large. Instead, import the container, then deploy the Trellix Agent to groups of systems at a time, rather than all at once.

  7. Select whether to delete systems from the System Tree when they are deleted from the NT domain. You can optionally choose to remove agents from deleted systems.

  8. To synchronize the group with the domain immediately, click Synchronize Now, then wait while the systems in the domain are added to the group.

    Clicking Synchronize Now saves changes to the synchronization settings before synchronizing the group. If you have an NT domain synchronization notification rule enabled, an event is generated for each system added or removed. These events appear in the Audit Log, and are queryable. If you selected to deploy agents to added systems, the deployment is initiated to each added system. When the synchronization is complete, the Last Synchronization time is updated. The time and date are when the synchronization finished, not when any agent deployments completed.

  9. To synchronize the group with the domain manually, click Compare and Update.

    1. If you are going to remove any systems from the group with this page, select whether to remove their agents when the system is removed.

    2. Select the systems to add to and remove from the group as necessary, then click Update Group to add the selected systems. The Synchronize Setting page appears.

  10. Click Save, then view the results in the System Tree if you clicked Synchronize Now or Update Group.

Once the systems are added to the System Tree, distribute agents to them if you did not select to deploy agents as part of the synchronization.

Consider setting up a recurring NT Domain/Active Directory synchronization server task to keep this group current with new systems in the NT domain.