The vastool group command looks for the samaccountname object in AD to add to the group. Since the samaccountname is unique the object is then added to the group as long as AD allows for it. For computer objects the samaccountname must be exact;
vastool -u admin group unix add hostname$
OIder versions of Authentication Services only allowed searching for users so an explicit path had to be used.
The "vastool group" command did not support adding or removing anything other than users from AD groups, however it is still possible to add other objects such as computers or other groups using this command. In order to add an object that is not a group, the object needs to be specified by its full canonical name or userPrincipalName. For example: