Home › Active Directory basics: how AD DS is built › Step 5

Organisational units (OUs) and the default AD DS containers

Step 5 of 6 in Active Directory basics: how AD DS is built · video 5:34

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

Organisational units are containers that admins create inside a domain to arrange users, computers and groups. This lesson gives the two main reasons for an OU: to apply Group Policy to everything in it by linking a GPO, and to delegate administrative control of its objects to a user or group without making them domain admins. It shows how OUs can mirror departments, regions or both, and that they are created in Active Directory Administrative Center. It then separates OUs from the generic containers AD DS creates on installation, such as Builtin, Computers, Users, ForeignSecurityPrincipals and Managed Service Accounts, and from the Domain Controllers OU, the only OU in a new domain. Containers cannot have GPOs linked to them. Hidden containers shown through Advanced Features, such as LostAndFound, Program Data and System, are listed as well. The lesson ends with hierarchy design: nest OUs by office and department, stay under ten levels and aim for five or fewer.

Check yourself

Answer in your head first, then open each question to see the answer.

1. Which OU exists in a brand-new AD DS domain, and what does it hold?

Only the Domain Controllers OU, which holds the computer accounts of the domain controllers. The other default objects created at installation, such as Users and Computers, are generic containers, not OUs.

2. What happens if you try to link a GPO to the default Users container to configure new staff accounts?

It is not possible, because generic containers cannot have GPOs linked to them. The accounts need to be moved into an OU, and the GPO linked to that OU.

3. How deep should an OU hierarchy go, according to the lesson?

There is no hard limit on levels, but it should stay at ten levels or fewer for manageability, and most organisations use five or fewer. Some applications that work with AD DS also restrict OU depth.

4. A company has three offices, each with its own IT admin and several departments needing different computer settings; how could its OUs be laid out?

Create one OU per office and, inside each, an OU for that office's IT administrators and one for each department. Control of each office OU can then be delegated to its local admin, and department-specific GPOs linked to the department OUs.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Introduction and Administration Tools

4.4★ · 10,857 students on Udemy

See the course on Udemy
← The AD DS domain: objects, replication, administration and sign-inNext: AD DS administration tools: ADAC, MMC snap-ins and PowerShell →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.