We want to use the AD-connector in sync mode to use UCS in parallel to an AD domain. While installing a new UCS system I chose the option to create a new UCS domain. After the installation was finished I used the Active-Directory-Connection module to set up the sync. After a few minutes the LDAP was completely synced. The manual says that by default only containers, users and groups are synced. Furthermore it explicitly says that computers are not synced. Nevertheless I see all computers from the AD domain in the UCS LDAP-browser.
I can confirm and reproduce that in my testingenvironment. It seems our documentation regarding this is outdated (we will correct that). Is the sync of the computer accounts at the moment a problem for you?
Thank you for the confirmation. I would prefer to not sync them because I don't need them. It's somehow annoying but doesn't cause any problems. I suppose it would be a solution to add computers to the UCR variable connector/ad/mapping/container/ignorelist and delete all synced computers, wouldn't it? (I have a bidirectional sync and don't want to delete the computer from the AD).
To stop new computers or modified ones from syncing, it should be sufficient to set:
ucr set connector/ad/mapping/computer/syncmode=none
and restart the service univention-ad-connector.