Already a NinjaOne customer? Log in to view more guides and the latest updates.

Active Directory Discovery and Deployment

Topic

This article describes the process for automatically discovering endpoints and deploying the NinjaOne agent to them via Active Directory.

Environment

NinjaOne Endpoint Management

Description

NinjaOne's Active Directory Discovery and Deployment tool allows technicians to automatically deploy the NinjaOne agent to devices that belong to a domain.

Only system administrators can approve or reject devices. If you move a Domain Controller from one organization to another, you must restart the NinjaOne agent on that domain controller in order for discovered devices to be installed in the new organization. To use a script to restart the Domain Controller, refer to Custom Script: Restart NinjaRMMAgent.

Index

Select a category to learn more:

Supported Client Operating Systems

NinjaOne supports the following operating systems (OSs) for discovery and deployment:

  • Microsoft Windows Vista
  • Windows 7
  • Windows 8.1
  • Windows 10
  • Windows 11
  • Server 2008r2
  • Server 2012/2012r2
  • Server 2016
  • Server 2019
  • Server 2022

Prerequisites

To run a discovery job on a Windows Server, that server must be running Active Directory and be a Domain Controller for that domain. If you select a workstation device for discovery but the job finds that the device's chassis or framework is for a server, nothing will happen, and the job may fail.

The Domain Controller used for discovery must have the NinjaOne agent installed.

You must have domain administrator credentials saved in the credentials store in the organization configuration. For more information, refer to NinjaOne Endpoint Management: Credential Exchange.

You must enable File and Printer Sharing on all client devices to push the Microsoft Software Installer (MSI). On Windows Vista, File Sharing is a separate setting from Printer Sharing, and only File Sharing is required. For more information on setting up File and Printer Sharing, you can view the following resource in the Microsoft forums: SMB - File and printer sharing ports should be open | Microsoft Learn (external link).

Client devices must be part of a domain and currently part of the network where the Domain Controller resides. Clients can sometimes be part of a domain but not be currently in the same network as the Domain Controller, in which case the agent deployment will fail.

Client devices must be online in order for Active Push to work; otherwise, a Group Policy Object (GPO) will be created with a startup script that will install the agent upon OS startup or reboot.

How to Run an Active Directory Discovery Job

You can run AD discovery jobs through the organization in NinjaOne.

  1. Navigate to Administration Organizations. Select the organization needing the ad-hoc discovery job. 
  2. From the organization configuration page, select Devices and open the Discovery Jobs tab. 
org_devices_add discovery job.png
Figure 1: Add a discovery job for the NinjaOne organization
  1. Click Add and select whether you want to run an immediate discovery job (ad hoc) or schedule the job for a future date and time. 
  2. Select your Domain Controller from the drop-down menu.
  3. When you select the Domain Controller, the folders for organizational unit (OU) paths related to the selected controller will display. Click through the folders to view their device information. Use the search field to find a specific OU path.
  4. Click Next.
Selecting Recursive will cause the job to also run on any child or secondary OUs, if applicable.
org_devices_ad hoc select devices.png
Figure 2: Select a device folder for your discovery job

On the Set Location and Status to New Devices screen, the workflow will change depending on whether you selected Adhoc Discovery or Scheduled Discovery

Select an option to view instructions: 

Run an ad hoc Discovery Job

If you selected Adhoc Discovery to create the job, continue with the following steps.

  1. Select the checkbox next to a device and click Select to configure the credentials for that device.
  2. Click Set Location and Status. There are several options for the status that can be applied to a device. Note that the status you choose affects all devices selected on the previous screen. Each device can have a different status within the same job. For more information about the device approval process, refer to NinjaOne Endpoint Management: Device (Node) Approval.

    StatusDefinition
    DiscoveredIdentifies devices that were newly discovered. No action occurs.
    PendingSets the selected devices as pending for deployment of the NinjaOne agent at a later time.
    ApprovedFlags the devices for instant installation of the NinjaOne agent.
    RejectedPrevents the selected devices from receiving the NinjaOne agent.
org_devices_add discovery job_set location and status.png
Figure 3: Provide the domain credentials for the device, and set the location and status
  1. Once you have selected the devices and set the credentials for location and status, click Apply
  2. Select the checkbox next to Save discovery job for later use to create a copy of the AD Discovery jobs. Click Yes to confirm this job.

    NinjaOne will not process more than one AD Discovery job at a time. Attempting to set up a second immediate job results in an error, as that Domain Controller or OU Path is already in use. Within a single job, you can assign different statuses to each device.

Schedule a Discovery Job

If you selected Scheduled Discovery to create the job, continue with the following steps.

  1. Set your credentials for the job and select a group of devices. Click Set Location and Status to choose the location and status for those devices. Note that the status you choose affects all devices selected on the previous screen. Each device can have a different status within the same job. For more information about the device approval process, refer to NinjaOne Endpoint Management: Device (Node) Approval. There are three options for scheduled Status:

    StatusDefinition
    NoneThe NinjaOne agent will not be deployed.
    Pending ApprovalNinjaOne will wait to deploy the agent until approved.
    Auto ApproveThe devices will be automatically approved, and the NinjaOne  agent will deploy when the scheduled job runs. 
  2. Click Set Schedule. This provides the option to configure when and how frequently the job runs. 
org_devices_add discovery job_set schedule.png
Figure 4: Set the schedule for the discovery job

There are four options when setting the schedule for an AD discovery job:

ScheduleDefinition
HourlyThis job will repeat every specified number of hours until all devices have successfully installed the NinjaOne agent.
DailyThis job will repeat every specified  number of days until all devices have successfully installed the NinjaOne agent.
WeeklyThis job will repeat every specified  number of weeks on specified days of the week until all devices have successfully installed the NinjaOne agent.
MonthlyThis job will repeat every specified  number of months on a specified day of the month until all devices have successfully installed the NinjaOne agent.
  1. When the job is configured, click Save.
  2. Give the job a unique identifier for the name and then click Confirm.

How to View AD Discovery Jobs

You can easily view all scheduled, current, and past discovery jobs from the organization configuration page.

  1. Navigate to AdministrationOrganizations. Select an organization, click Devices and open the Discovery Jobs tab. 
  2. The Lists tab displays current ad hoc or scheduled jobs:

    ColumnDescription
    NameThe title given to that job.
    TypeAdhoc or Scheduled.
    Domain ControllerThe domain controller being used for this job.
    OU PathThe OU Path for the device(s).
    ScheduleWhen the job is scheduled to run (for scheduled jobs only).
    org_list of discovery jobs.png
    Figure 5: View current and scheduled discovery jobs
  3. The History tab displays previously completed jobs along with a summary of those jobs:

    ColumnDescription
    NameThe title given to that job.
    TypeAd hoc or scheduled.
    DateThe date the job was completed.
    SummaryA summary of what actions were involved.
    UserThe technician who created the job.
    org_history of discovery jobs.png
    Figure 6: View completed discovery jobs

How to Cancel or Update AD Discovery Jobs

You can cancel or update scheduled discovery jobs that have not started. To do so, perform the following steps.

The job does not appear in the History tab if you delete it before it has run.
  1. Navigate to AdministrationOrganizations. Select an organization, click Devices and open the Discovery Jobs tab.
  2. Place your cursor over the job you wish to manage and select Edit or Delete as applicable.

    edit or delete AD discovery job.png
    Figure 7: Edit or delete a scheduled discovery job

Additional Resources

To learn more about how to manage your endpoints in NinjaOne, refer to NinjaOne Endpoint Management: Device Enrollment & Management: Resource Catalog.

FAQ

Next Steps