diff --git a/ad-auth/tasks/kerberos.yml b/ad-auth/tasks/kerberos.yml
index 8884d53668e833e8aa454924a983e44136183875..cb87ae888cc9ebd0f522f30aa64b2abd609d69eb 100644
--- a/ad-auth/tasks/kerberos.yml
+++ b/ad-auth/tasks/kerberos.yml
@@ -3,8 +3,12 @@
 
 #- name: ensure kerberos is installed
 #  apt: name=krb5-user,krb5-clients state=latest
-#  tags: kerberos packages
+#  tags:
+#    - kerberos
+#    - packages
 #
 #- name: configure kerberos
 #  template: src=krb5.conf.j2 dest=/etc/krb5.conf owner=root group=root mode=0644
-#  tags: kerberos config
+#  tags:
+#    - kerberos
+#    - config
diff --git a/ad-auth/tasks/ldap.yml b/ad-auth/tasks/ldap.yml
index 20d289b6b207fe8409459038cf6d8910ee24a2b3..9d2a6eac0cf36bd037da3e4cf095892a480f9fb1 100644
--- a/ad-auth/tasks/ldap.yml
+++ b/ad-auth/tasks/ldap.yml
@@ -3,12 +3,19 @@
 
 - name: ensure old libnss-ldap and libnss-pam are not installed
   apt: name=libnss-ldap,libpam-ldap state=absent
-  tags: packages clean ldap
+  tags:
+    - packages
+    - clean
+    - ldap
   
 - name: ensure ldap NSS and PAM modules are installed
   apt: name=libnss-ldapd,libpam-ldapd,ldap-utils state=latest
-  tags: ldap packages
+  tags:
+    - ldap
+    - packages
 
 - name: ensure proper global ldap configuration
   template: src=ldap.conf.j2 dest=/etc/ldap/ldap.conf owner=root group=root mode=0644
-  tags: ldap config
+  tags:
+    - ldap
+    - config
diff --git a/ad-auth/tasks/nscd.yml b/ad-auth/tasks/nscd.yml
index bce387aa939bf1abe8aa190f50a7a431cc8a5c6f..32d43d4ca49a4dd457f27d23a8a24f23f5595b60 100644
--- a/ad-auth/tasks/nscd.yml
+++ b/ad-auth/tasks/nscd.yml
@@ -3,22 +3,30 @@
 
 - name: ensure nscd is installed
   apt: name=nscd state=latest
-  tags: nscd packages
+  tags:
+    - nscd
+    - packages
 
 - name: ensure proper nscd configuration
   copy: src=nsswitch.conf dest=/etc/nsswitch.conf owner=root group=root mode=0644
   notify:
     - restart nscd
     - clear nscd caches
-  tags: nscd config
+  tags:
+    - nscd
+    - config
 
 - name: ensure a happy nscd
   file: path=/etc/netgroup state=touch
   notify:
     - restart nscd
     - clear nscd caches
-  tags: nscd config
+  tags:
+    - nscd
+    - config
 
 - name: ensure nscd is running
   service: name=nscd state=running enabled=yes
-  tags: nscd service
+  tags:
+    - nscd
+    - service
diff --git a/ad-auth/tasks/nslcd.yml b/ad-auth/tasks/nslcd.yml
index 8579fd47d7f3f695707080d875114f3172116116..f8d15be3fac5880c37df3fd990edb3a76b906804 100644
--- a/ad-auth/tasks/nslcd.yml
+++ b/ad-auth/tasks/nslcd.yml
@@ -3,14 +3,20 @@
 
 - name: ensure nslcd is installed
   apt: name=nslcd state=latest
-  tags: nslcd packages
+  tags:
+    - nslcd
+    - packages
 
 - name: ensure proper nslcd configuration
   template: src=nslcd.conf.j2 dest=/etc/nslcd.conf owner=root group=nslcd mode=0640
   notify:
     - restart nslcd
-  tags: nslcd config
+  tags:
+    - nslcd
+    - config
 
 - name: ensure nslcd is running and enabled
   service: name=nslcd state=running enabled=yes
-  tags: nslcd service
+  tags:
+    - nslcd
+    - service
diff --git a/ad-auth/tasks/sudo.yml b/ad-auth/tasks/sudo.yml
index 761d91b36a8f9a44d261b71a853a1804613f8f16..d6fa4518c66c6cfb6f015ab6f028c1a81404183d 100644
--- a/ad-auth/tasks/sudo.yml
+++ b/ad-auth/tasks/sudo.yml
@@ -3,8 +3,12 @@
 
 - name: ensure users of group admin are in the sudoers
   copy: src=sudo/admin dest=/etc/sudoers.d/admin owner=root group=root mode=0440
-  tags: sudo config
+  tags:
+    - sudo
+    - config
 
 - name: check whole sudo config
   command: visudo -q -c -f /etc/sudoers
-  tags: sudo test
+  tags:
+    - sudo
+    - test
diff --git a/nfs-client/tasks/main.yml b/nfs-client/tasks/main.yml
index e6467da461ebcca9d32651aca2484c9969cc7ca2..f7165b8159d54bb293dcccd0ebb07c2906a21a66 100644
--- a/nfs-client/tasks/main.yml
+++ b/nfs-client/tasks/main.yml
@@ -3,36 +3,56 @@
 
 - name: ensure nfs client utils are installed
   apt: name=nfs-common state=latest
-  tags: nfs-client packages
+  tags:
+    - nfs-client
+    - packages
 
 - name: ensure CIFS utils are installed
   apt: name=cifs-utils,smbclient state=latest
-  tags: cifs-client packages
+  tags:
+    - cifs-client
+    - packages
 
 # makes life much easier to have an automounter and not /etc/fstab
 - name: ensure automounter is installed
   apt: name=autofs state=latest
-  tags: autofs packages
+  tags:
+    - autofs
+    - packages
 
 - name: ensure automounter is configured
   copy: src=auto.master dest=/etc/auto.master owner=root group=root mode=0644
   notify:
     - restart autofs
-  tags: autofs config
+  tags:
+    - autofs
+    - config
 
 - name: ensure mounts from central storage are available
   template: src=auto.nfs.j2 dest=/etc/auto.nfs owner=root group=root mode=0644
   notify:
     - restart autofs
-  tags: autofs config
+  tags:
+    - autofs
+    - config
+
+- name: ensure automounter is enabled
+  service: name=autofs state=running enabled=yes
+  tags:
+    - autofs
+    - service
 
 - name: ensure linking of home
   script: create_netdir.sh home
-  tags: fsmpi
+  tags:
+    - fsmpi
+    - autofs
 
 - name: ensure linking of pub
   script: create_netdir.sh pub
-  tags: fsmpi
+  tags:
+    - fsmpi
+    - autofs
 
 - meta: flush_handlers
 - include: umask.yml
diff --git a/nfs-client/tasks/umask.yml b/nfs-client/tasks/umask.yml
index f102342b4c8d2fed2ca32eb609f242084e8275f7..8d722566d02f2f7168e51575e4409592ed9a452c 100644
--- a/nfs-client/tasks/umask.yml
+++ b/nfs-client/tasks/umask.yml
@@ -3,6 +3,13 @@
 
 - name: configure default umask and other user related stuff
   copy: src=login.defs dest=/etc/login.defs owner=root group=root mode=0644
+  tags:
+    - umask
+    - config
 
 - name: activate pam.d session modules to set default umask
   copy: src=pam_common-session dest=/etc/pam.d/common-session owner=root group=root mode=0644
+  tags:
+    - umask
+    - pam
+    - config