What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
To enable SCCM (now called Configuration Manager) Active Directory User Discovery and exclude a child OU, open Administration → Hierarchy Configuration → Discovery Methods, select Active Directory User Discovery, and choose Properties. On General, enable the method and add the parent OU. In that location’s settings, enable recursive search if needed, then choose Select sub containers to be excluded from discovery → Add and select the child OU. OU exclusions are supported starting in Configuration Manager version 2103. They apply to that discovery location; they are not a global rule or a command to delete existing user records.
What Active Directory User Discovery does
Active Directory User Discovery searches specified Active Directory Domain Services locations for user accounts and selected attributes, then creates or updates user resource records in the Configuration Manager database. It can discover a user name, unique user name including the domain, domain, Active Directory container names, and additional attributes configured on the Active Directory Attributes tab. See Microsoft’s discovery methods overview.
Discovery identifies accounts and information; it does not install the Configuration Manager client on users and does not replace computer discovery. Keep the methods distinct:
Recommended Free Tools
- Active Directory User Discovery finds user accounts in the configured AD locations.
- Active Directory System Discovery finds computer accounts.
- Active Directory Group Discovery finds groups and memberships. It can return limited details about users or computers that are group members, but it is not a substitute for full User Discovery.
- Microsoft Entra user discovery finds cloud identities and is configured through Cloud Management/Azure Services, not the on-premises OU dialog.
“SCCM” is a familiar legacy name; Microsoft’s current documentation calls the product Configuration Manager.
#1 Best Overall
- 3.5 Inch Hot Plug Hard Drive PowerEdge T340 Tower Server Chassis
- Microsoft Windows Server 2019 Standard Operating System
- Processors: Intel Xeon E-2124 Quad-Core 3.3GHz 8MB CPU, Up To 4.3GHz Turbo
- Memory: 32GB (2 x 16GB) DDR4 PC4-21300 2666MHz Unbuffered Memory
- Hard Drive: 8TB (4 x 2TB) 7.2K RPM 6Gb/s SATA 3.5 Inch HDDs in RAID
Before you begin
- Use a Configuration Manager primary site and an account permitted to configure discovery methods in the console.
- Decide which users the management task actually requires. Add only the necessary AD locations rather than searching a broad domain or forest by default.
- Have a valid LDAP path to the intended container or OU and choose whether its child containers should be searched recursively.
- Choose a discovery account: a Windows user account or the site server computer account. The selected account needs Read access to the specified AD locations. See Microsoft’s Configuration Manager account guidance.
- Plan a sensible schedule. AD polling and processing create network and site workload; overly frequent full discovery can affect AD, the network, and Configuration Manager.
Enable Active Directory User Discovery
- Open the Configuration Manager console.
- Go to Administration → Hierarchy Configuration → Discovery Methods.
- Select Active Directory User Discovery for the relevant primary site, then select Properties on the ribbon.
- On the General tab, select the checkbox to enable the method. You can configure its locations before enabling it if you prefer to review the scope first.
These are the current console labels and path in Microsoft’s discovery configuration documentation.
Add the parent OU or container
- On the General tab, select New.
- Specify the container or organizational unit to search. The location must be a valid LDAP path, such as
LDAP://OU=Users,DC=contoso,DC=com. - Select the discovery account with Read access to that location.
- Decide whether to search child containers recursively. Recursion is what makes exclusions of nested OUs useful when you want to search most of a parent tree but omit selected branches.
For example, if the configured location is OU=Users,DC=contoso,DC=com, it might contain:
OU=Users,DC=contoso,DC=com
├── OU=Employees
├── OU=Contractors
└── OU=Service Accounts
If the parent is searched recursively and OU=Service Accounts is excluded, the intended outcome is to omit that child container from this discovery location while retaining the other in-scope branches.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchExclude a child OU
The exclusion control is inside the settings for an individual AD container; it is not a separate discovery method.
Rank #2
- Windows server license is not included
- In the Active Directory Container dialog, enable recursive searching if you want to search the parent’s child containers.
- Select Select sub containers to be excluded from discovery.
- Select Add, then select the child OU to exclude.
- Select OK to save the exclusion, then OK again to save the container settings.
- Select OK on the discovery properties page to save the configuration.
OU exclusion for Active Directory User Discovery is supported from Configuration Manager version 2103. Starting in version 2203, exclusions also support subcontainers in untrusted domains. If the exclusion option is missing, check the site version, confirm that you are editing Active Directory User Discovery, and open the settings for the specific container rather than looking for a separate global exclusion list.
Set the polling schedule and attributes
On the Polling Schedule tab, configure full discovery and, where appropriate, delta discovery. Full discovery performs a broader search of the configured locations; delta discovery checks for changes between full cycles. Saving the configuration does not itself mean the next full search has completed. Microsoft recommends using delta discovery more frequently than full discovery where suitable and cautions against unnecessarily aggressive polling. Management-insights guidance says full Active Directory User Discovery generally should not run more frequently than every three hours; this is operational guidance, not a universal product limit. Review the configuration guidance and Configuration Manager performance recommendations for your environment.
On the Active Directory Attributes tab, review the default attributes and add custom attributes only when a query, collection, or report needs them. Unneeded attributes increase the data collected and processed.
Verify the scope and results
- Reopen Administration → Hierarchy Configuration → Discovery Methods → Active Directory User Discovery → Properties.
- Confirm that the method is enabled, the parent location and discovery account are correct, recursion matches your intention, and the excluded OU is listed. The discovery-location list can show a Has Exclusions indicator.
- Wait for the next scheduled discovery, or use the console’s available discovery action if appropriate. Allow time for discovery data to be processed by the site.
- In the Users node, check an account from an included OU and an account from the excluded OU. Confirm that included users appear or update as expected, and that the excluded account is not newly discovered through this particular location.
- On the site server, review
adusrdis.logfor Active Directory User Discovery activity and errors. Microsoft lists this as the log for the method in its discovery overview.
Do not treat a user resource already visible in Configuration Manager as proof that the exclusion failed. The exclusion controls searching through its configured location; it does not automatically delete existing resource records, and another discovery source may also create or update the resource.
Rank #3
- MODEL P74439-005: Compact and affordable HPE ProLiant MicroServer Gen11 powered by Intel Pentium Gold G7400 3.7GHz processor, ideal for file sharing, NAS, and basic business workloads
- READY OUT OF THE BOX: Includes 16GB DDR5 UDIMM memory (expandable to 128GB), one 1TB SATA 6G Business Critical HDD, embedded Intel VROC SATA, dedicated iLO-M.2 port kit, 180w external power adapter and 1/1/1 warranty for dependable plug-and-play server operation
- WHISPER-QUIET & SPACE-SAVING: Ultra-compact mini tower design fits easily in small office spaces; supports wall, flat, or vertical placement for deployment flexibility
- INTEGRATED REMOTE MANAGEMENT: Comes with HPE iLO 6 and embedded TPM 2.0 for secure, license-free remote server administration through shared port access
- EXPANDABLE DESIGN: Two PCIe slots (including PCIe 5.0) and four LFF-NHP drive bays provide robust options for storage and component scalability. Features new MR408i-p controller support for enhanced storage performance
What an OU exclusion does—and does not do
An exclusion prevents the specified child container from being searched by that recursive discovery scope. It lets you retain a broad parent location while omitting selected subcontainers, and different configured locations can have their own settings and discovery accounts.
It does not delete the OU in AD, hide it from administrators, automatically remove existing Configuration Manager user resources, or prevent the same user from being found through another overlapping User Discovery location. Nor is it a hierarchy-wide deny rule for Active Directory Group Discovery or Microsoft Entra user discovery. These other methods have their own scopes; review them when a user remains visible.
If users from the excluded OU still appear
- Check the OU’s identity and position. Verify its distinguished name and confirm that the selected OU is actually beneath the configured parent location.
- Review recursion and the saved exclusion. Reopen the container settings and ensure the excluded OU is listed. If the configured location itself is the unwanted OU, removing that location or disabling recursion may be clearer than excluding a child.
- Look for overlapping User Discovery locations. Review every container entry; another parent path may include the same OU.
- Check Active Directory Group Discovery. A user who belongs to a discovered group can have a limited user record created or updated through group discovery. Review its scope and memberships.
- Check Microsoft Entra user discovery if the identity is also represented in the cloud and that method is configured.
- Consider existing records. An OU exclusion is not an automatic cleanup action. Confirm discovery activity in
adusrdis.logand distinguish an older resource from a newly discovered one.
If discovery fails with access or authentication errors
Confirm which discovery account is configured and that it has Read access to the parent location and objects being searched. If the site server computer account is selected, verify that it is the intended account and has the required permissions. Check for an expired user-account password and, for cross-domain paths, validate the relevant trust and access conditions. Review adusrdis.log for the specific failure before changing permissions broadly.
Reduce discovery load
Keep the scope narrow, avoid overlapping locations, run full discovery at a reasonable interval, and add only useful attributes. Avoid broad forest searches or very short full-discovery intervals when a smaller scope and delta discovery meet the need. Microsoft’s performance guidance discusses the impact of discovery scheduling and scope.
Rank #4
- This Certified Refurbished product is tested and certified to look and work like new. The refurbishing process includes functionality testing, basic cleaning, inspection, and repackaging. The product ships with all relevant accessories, a minimum 90-day warranty, and may arrive in a generic box. Only select sellers who maintain a high-performance bar may offer Certified Refurbished products on Amazon.com.
- Dell Optiplex 3050 SFF Desktop computer PC, Intel Quad Core i5-6500 up to 3.6GHz, 16GB DDR4, 256GB SSD
- Includes: USB Keyboard & Mouse, USB WiFi adapter, Microsoft office 30 days free trail.
- Port: Front: USB 3.0(2), USB 2.0(2); Rear: DP, HDMI, USB 3.0(2), USB 2.0(2), RJ-45.
- Support 4K (3840x2160) Dual display, makes it easy to connect two monitors at the same time, and you can expand working Windows, mirror content, or expand a single window across multiple monitors.
On-premises AD discovery or Microsoft Entra discovery?
| Need | Use |
|---|---|
| Discover traditional on-premises AD users in selected OUs | Active Directory User Discovery |
| Exclude child OUs from an on-premises AD search | Active Directory User Discovery’s container exclusion |
| Discover cloud identities from Microsoft Entra ID | Microsoft Entra user discovery, configured through Cloud Management |
| Manage synchronized or federated identities in a hybrid scenario | Depending on the scenario, both AD and Entra discovery may be needed |
Microsoft notes that Entra user discovery is configured when the site is onboarded to Microsoft Entra ID, and synchronized or federated identity scenarios can require both discovery methods. See discovery configuration for details. Entra discovery is not configured through the on-premises OU exclusion dialog.
PowerShell and automation
The ConfigurationManager PowerShell module includes Set-CMDiscoveryMethod, with an -ActiveDirectoryUserDiscovery parameter. Microsoft documents options for modifying discovery-method settings and containers; run Configuration Manager cmdlets from the site drive, for example PS XYZ:>. See the Set-CMDiscoveryMethod reference.
For OU exclusions, use the console procedure above unless you have a script validated for your site’s exact Configuration Manager version. Do not assume that a container-setting example also creates the required exclusion: validate the resulting discovery properties and test the scope before relying on automation in production.
Quick Recap
Configuration checklist
- Correct primary site selected and Active Directory User Discovery enabled.
- Only the intended parent OU or container is configured.
- Recursive search is intentional, and the child OU exclusion is saved on the correct location.
- The discovery account has Read access to the required AD locations.
- Polling and selected attributes are proportionate to the need.
- Included and excluded test users and
adusrdis.loghave been checked. - Other discovery scopes and existing user records have been considered before concluding that the exclusion did not work.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

