The Scope defines the set of objects upon which to execute the actions of the Scope Action. It can be a set of machines, users or groups.

Note: You can further fine tune which objects within a Scope will be processed by using Conditions.

Select an Object Type

A Scope is first defined by an object type: Users, Groups or Computers. Click on the desired object type button in the Target Object Type section. You should do that before you define the Scope. Once you have defined the object type, you need to define the actual set of objects for this Scope Action.

Using Scope Templates

If you have Scope Templates objects, you can drag and drop them from the template area to the Scope area.

If you haven't yet defined a template, you need to create a new Scope definition. To create a new Scope template, either double-click the Add New button in the Scope Template area, or, click the Add New button in the Scope area and once defined, drag and drop the Scope object to the Template area.

Sharing Scope Templates

Once Sharing has been configured, you can share your Scope templates to make them available to everyone belonging to your Goverlan Workgroup.
Select a Scope template from the Template area and click the  button to share or unshare the object.


Creating a new Scope Definition

Click the Add New button to create a new Scope definition, enter a name to define this Scope object and define the scope.
Depending on the selected object type, Goverlan offers miscellaneous methods to define the set of objects.

Add a Container or Domain

Available for all object types, this method allows you to define a list of objects by selecting an Active Directory container or domain.

  • Select the domain or container you wish to include in the Scope

  • Enable the Include sub-containers option if you wish to include every child container, or, disable this option to only include the objects contained at the root of the selected container.

  • Optionally configure a Name Filter. A name filter is a simple string with NO wildcard. The object's name must contain the specified text to be included in the set.

  • Click on OK.

Add Input File

Available for all object types, this method allows you to define a list of objects based on an input file. The contents of the input file are queried during execution. For this reason, the input file's contents can change between Scope Actions executions.

The input file must contain one entry per line. Do not use quotes or double-quotes to define each entry. The format for each entry can either be a UNC Name (i.e.: DOMAINAccountID), or, a simple name (for computer objects only), or, an active directory bindstring (i.e.:LDAP://cn=Object Name, cn=Container, dc=my, dc=domain, dc=com).

Click the Add Container or Domain link to insert an entire container into the Scope. A container can be an Active Directory domain, container or organizational unit or an NT domain. When inserting an Active Directory container in the Scope, you also have the option to include all sub-containers as well.

Add individual Objects

Available for all object types, this method allows you to define a list of objects by selecting them individually from Active Directory.

If you are defining a Computer Scope, this method also allows you to define a list of computers via an IP subnet scan. This method is slightly different than selecting the Add an IP Range method (see below) because it defines a static list of found IPs, while adding an IP range defines a dynamic scope (the IP range is scanned during execution).

Note: While selected individual objects using the Goverlan Object Selector, you can select a Group of objects as well. The group members will be queried at execution time.

Add an IP Range

Available only for computer objects, this method allows you to define an IP range to be scanned at execution time. The IP addresses that fulfill the configured criteria (i.e., is alive, resolves to a name) are used for the Scope.

Add an Active Directory Site

Available only for computer objects, this method allows you to define the Scope based on an Active Directory Site. As with the IP Range definition, you can configure criteria on the IP addresses that belong to the selected site.