Home › Active Directory basics: how AD DS is built › Step 5
Organisational units (OUs) and the default AD DS containers
Step 5 of 6 in Active Directory basics: how AD DS is built · video 5:34
What you will learn
- The two reasons to create an OU: Group Policy and delegation
- How OUs differ from built-in containers such as Users and Computers
- Which default containers exist and which are hidden
- How deep an OU hierarchy should go
About this lesson
Organisational units are containers that admins create inside a domain to arrange users, computers and groups. This lesson gives the two main reasons for an OU: to apply Group Policy to everything in it by linking a GPO, and to delegate administrative control of its objects to a user or group without making them domain admins. It shows how OUs can mirror departments, regions or both, and that they are created in Active Directory Administrative Center. It then separates OUs from the generic containers AD DS creates on installation, such as Builtin, Computers, Users, ForeignSecurityPrincipals and Managed Service Accounts, and from the Domain Controllers OU, the only OU in a new domain. Containers cannot have GPOs linked to them. Hidden containers shown through Advanced Features, such as LostAndFound, Program Data and System, are listed as well. The lesson ends with hierarchy design: nest OUs by office and department, stay under ten levels and aim for five or fewer.
Check yourself
1. Which OU exists in a brand-new AD DS domain, and what does it hold?
Only the Domain Controllers OU, which holds the computer accounts of the domain controllers. The other default objects created at installation, such as Users and Computers, are generic containers, not OUs.
2. What happens if you try to link a GPO to the default Users container to configure new staff accounts?
It is not possible, because generic containers cannot have GPOs linked to them. The accounts need to be moved into an OU, and the GPO linked to that OU.
3. How deep should an OU hierarchy go, according to the lesson?
There is no hard limit on levels, but it should stay at ten levels or fewer for manageability, and most organisations use five or fewer. Some applications that work with AD DS also restrict OU depth.
4. A company has three offices, each with its own IT admin and several departments needing different computer settings; how could its OUs be laid out?
Create one OU per office and, inside each, an OU for that office's IT administrators and one for each department. Control of each office OU can then be delegated to its local admin, and department-specific GPOs linked to the department OUs.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.