Tys Posted March 26, 2014 Posted March 26, 2014 Hi all, I'll be starting at a small school soon to sort out the mess that County left them with (standalone machines, no internet filtering, broken shared drives, broken printing, one wireless ap with WEP [wonder how many people are enjoying that free internet, grr], dodgy internet, gah). One of the first things I'll be doing will be getting a basic domain set up and all machines joined (or upgraded to versions that can, since some are still on home versions of Windows), but I'd like some advice on the OU structure to use. What I'd think to do is below, but I'd like to see what other people do and what your opinions on this are, since I'm generally pretty awful at organizing. Cheers. -School Name --[b]Students[/b] ---Intake year x ----Johnny Test (username: testj) ---[b]Leavers[/b] ----Intake year x --[b]Staff[/b] ---Teaching ----Joe Bloggs, Teacher of x (username: bloggsj) ---Non-teaching ---Admin --[b]Workstations[/b] ---Laptops (not sure if it's worth differentiating between teacher and student here?) ---Desktops ---Admin
caffrey Posted March 26, 2014 Posted March 26, 2014 Pretty much similar to mine, however I split the PCs up into curriculum groups too, easier for GPO etc.
Techie-v2 Posted March 26, 2014 Posted March 26, 2014 Pertty much the same but we split the computer right down to locations, so an OU for department then an OU for each room in that deparment
Chris_Jones Posted March 26, 2014 Posted March 26, 2014 (edited) I would always split pupil machines from teacher machines, then depending on numbers, split by area / room / laptop trolley if needed. also for pupil usernames, consider something like (2DigitIntakeYear)(Surname)(Initial) it makes it easier to identify where the pupil is in AD from their username and cuts down on duplicates. Edited March 28, 2014 by ZeroHour
witch Posted March 26, 2014 Posted March 26, 2014 Again, pretty similar. I have rooms/netbook trolleys etc split off as necessary and teacher laptops and SEN computers as a separate group as well
Tys Posted March 26, 2014 Author Posted March 26, 2014 I would always split pupil machines from teacher machine I see this done a lot but never really understood why pupil machines and teacher machines need to be treated any differently? They run the same stuff as the pupil machines.
Steve21 Posted March 26, 2014 Posted March 26, 2014 I see this done a lot but never really understood why pupil machines and teacher machines need to be treated any differently? They run the same stuff as the pupil machines. Some sites we do, some we don't, depending on how we're deploying software etc Things like whiteboard software etc etc, we only deploy to teachers blahblah. Steve
smidsy Posted March 26, 2014 Posted March 26, 2014 Our structure is fairly similar but we do split pupil and teacher laptops as they receive some different software which is deployed through GPO.
localzuk Posted March 26, 2014 Posted March 26, 2014 We split PCs into Admin and Curriculum, and then sub-OU by room.
TechMonkey Posted March 26, 2014 Posted March 26, 2014 I see this done a lot but never really understood why pupil machines and teacher machines need to be treated any differently? They run the same stuff as the pupil machines. I guess you could do it as future proofing. You may not have any need now but what about down the line and will it be a major hassle shifting things if you don't do it at the start. As long as they are under a single OU higher you can treat them the same. The only additional OU I had was for Groups. Just as a handy place to store them more than anything.
Miscbrah Posted March 26, 2014 Posted March 26, 2014 We split PCs into Admin and Curriculum, and then sub-OU by room. We do similar, but some ICT suites into further sub-OUs for students PCs and teacher PCs for the sake of LanSchool. Yours seems sensible yeah.
Jasbo Posted March 26, 2014 Posted March 26, 2014 +1 for a groups ou to keep all user groups in a sub uo under the school site, always do that. Helps keep it tidy.
tmcd35 Posted March 27, 2014 Posted March 27, 2014 I tend to go for something a bit more granular.. domain ...site name ......Computers .........Staff ............ ............ ............... ............ ................ .........Pupils ............ ......Users .........Staff ............Admin ............Teaching ................ .........Students ............. ......Groups .........Security .........Email ......Network .........Computers .........Servers .........Users .........Groups ......Terminal Servers This allows better targeting of GPO's. I tend to use 4 types of GPO - Security, Internet, Software Install, Printers. So I can set a Printer GPO at the Computers/Staff level so all teacher get the staffroom printer. Or an Internet GPO at Users/Students/Year 7 so they get more restrictions. Or whatever.
pcstru Posted March 27, 2014 Posted March 27, 2014 @tmncd35 how did you create OU's within Users and Computers? Does it cause you any issues?
tmcd35 Posted March 27, 2014 Posted March 27, 2014 Sorry for the confusion. At the domain level (same level as the Users and Computers you are refering to) I have single OU that is the name of the school. I then have all other OU's within that. So... Domain/School/Computers/Students not Domain/Computers/Students. 1
themightymrp Posted March 27, 2014 Posted March 27, 2014 Ours is similar to the above: Domain ---Machines -----Staff -------Admin -------Laptops -----Students -------IT1 -------IT2 -------etc ---Users -----Administrators -----Staff -----Students -------Year 7 -------Year 8 -------etc ---Servers -----Admin (with IPsec) -----Curriculum There is more fine tuning than this but as a general overview..
mcrompton01 Posted March 27, 2014 Posted March 27, 2014 (edited) Ours is: DOMAIN ---Computer Accounts ------Admin Office ---------Office 1, 2,3 etc ------Department ---------Room ---------Staff Laptops ---------Student Laptops (Trolleys for example) ------Test Machines (for software deployment etc) ---Contacts (contacts for teachers in our partner school - ease of use in exchange) ---Groups (Standard security groups for shared area etc) ---Groups - Applications (each piece of software has a security group so we can allocate anything to anywhere, we use SCCM) ---Groups - Classes (sync'd with SIMS each class has a security group we use this for papercut and account selection) ---Groups - Distribution (exchange distribution groups) ---Groups - Intranet (access control for the intranet) ---Groups - Printers (using groups and GPP for printer allocation) ---Member Servers ---Remote Access Servers (Terminal Servers) ---Service Accounts ---User Accounts ------Staff ------Students ---------Year of Entry ------Third Party ---------Primary School Visits ---------Open Evening ---------OFSTED ---------etc.... ------System Administrators and that's about it! Edit: Added System Administrators, no idea how I forgot that one! Edited March 27, 2014 by mcrompton01
Tys Posted March 29, 2014 Author Posted March 29, 2014 @mcrompton01 Surely it would be better to drop all those Groups OUs into their own big OU though, otherwise they'd clutter up the root domain? I may do something like what you've done with Groups - Applications though, seems like that'd be a good way to organize software deployment. Thanks for replies everyone, extremely helpful!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now