Is it possible to assign a Managed Installation to a Active Drirectory group.
Here is the plan.
Create a group in AD assign users to group in AD then create a Managed Install and assign it to the AD group
User is just to login as they normally do and if the application is not installed on the computer then it will install the app.
Just have to manage users in AD to assign applications.
Is this possible?
Community Chosen Answer
This is, in fact, possible. You can create an LDAP Device Label that is populated based on the user that is logged in. Granted, this would get kind of tricky on shared workstations, but if you generally have a 1:1 relationship of PC to User, then you should be fine.
We have several LDAP Device Labels that are based on the user. Here is one example:
Base DN: DC=domain,DC=org
Filter: (&(sAMAccountName=KBOX_USERNAME)(memberOf=CN=IS Staff,OU=Groups,DC=domain,DC=org))
As you can see, we're filtering on KBOX_USERNAME, which when run as a device label, contains the currently logged in user, and we're checking to see if that user is a member of our IS Staff group.