Skip to content

Duplicate assets from incomplete discovery

If the same asset shows up as multiple, separate objects in vScope — commonly seen with Nutanix VMs, Active Directory computer objects, and Azure/Entra ID devices — this page helps you confirm that incomplete discovery is the cause, then close the credential/permission gap so vScope can merge the records into one asset.

vScope merges records from different data sources into a single asset through stitching, matching on attributes such as domain, device ID, serial number, and hostname (see Assets). If a discovery run only fetches part of these attributes — because a credential lacks the required permissions, the discovery scope is limited, or the run is aborted early — vScope doesn’t have enough matching information to confirm it’s the same object. The result is two (or more) partial records for what is really one asset, which looks like a duplicate.

This is different from:

  1. Open a table showing the duplicated assets and add the key identifying columns for the data source, e.g. Domain, Azure AD Device ID, or Intune Device ID.
  2. Compare the rows:
    • If one row has empty or partial values in these columns compared to the other → the cause is incomplete discovery; continue below.
    • If both rows have full, genuinely different IDs → they’re separate objects in the source system and should be investigated there instead.

Check discovery completeness per data source

Section titled “Check discovery completeness per data source”
  • Confirm the credential can read all users, groups, and computer objects — see Active Directory requirements.
  • If Search Base DN is limited to a sub-tree, objects outside it are skipped entirely. Verify the scope covers the OUs the duplicated objects live in — see Find Base DN setting.
  • Confirm the app registration still has the required Graph API permissions — including AdvancedQuery.Read.All and Machine.Read.All for Defender — with admin consent granted. See Windows Defender.
  • If Defender Device Discovery is enabled, it can import devices with incomplete information by design, which inflates counts. Review and filter it under security.microsoft.com → System → Settings → Endpoints → Advanced features.
  • See Azure discovery issues for domain-matching checks and the Merge Duplicate Devices setting.
  • Confirm the Nutanix credential’s role (e.g. Prism Viewer) has read access to the full VM, cluster, and host inventory, not just a subset — see Nutanix setup.
  • Confirm the discovery target points at Prism Central rather than an individual Prism Element, so all clusters are inventoried consistently.
  1. Correct the credential, permission, or scope issue identified above.
  2. Run a full rediscovery of the affected data source (Discovery Manager → select the credential → Rediscover).
  3. Re-check the columns from Confirm it’s incomplete discovery — the two rows should merge into one asset once both carry matching identifying attributes.
  4. If duplicates remain after a complete discovery, the cause is more likely a domain-matching or configuration issue rather than missing data — follow Duplicate Assets to review Discovery Suggestions or create a custom domain-matching rule.