Gongalong Posted June 15, 2012 Posted June 15, 2012 Hi folks, Am I right in thinking that OUs within group policies are completely separate from OUs within AD? If so, why create OUs within the GP editor? And how do OUs within the GP editor affect the priority in which GPOs are applied? Sorry, I'm confused! TIA
FN-GM Posted June 15, 2012 Posted June 15, 2012 1. They are the same 2. N/A 3. The lower down the OU the higher priority will the setting be. If you set enabled on a setting in an ou but on the same setting on a sub ou you selected disabled it will apply the sub ou settings. 1
Gongalong Posted June 16, 2012 Author Posted June 16, 2012 Am I going mad though, because there are no OUs in the GPM by default. Certainly none that mirror those in the AD.
plexer Posted June 16, 2012 Posted June 16, 2012 If you create an OU in ADUC then it will be available to apply GPO to in GPMC. You may be confusing an OU with a regular container. What is the difference between a Container and an OU in Active Directory? - Yahoo! Answers Ben 1
Gongalong Posted June 16, 2012 Author Posted June 16, 2012 Ahhh, I inherited this system (already mostly setup), and my server knowledge is a bit rusty. I had assumed that if a container was created within AD it was essentially an OU by default. Presumably everything within AD is a container then, because nothing is replicated in GPM.
Gongalong Posted June 16, 2012 Author Posted June 16, 2012 Is this the only reason to create an OU, instead of a container? i.e. for use with GPM.
Gongalong Posted June 18, 2012 Author Posted June 18, 2012 (edited) Presumably a container is described as a "shared folder" in AD? Would there be any dangers of taking users/computers from shared folders and putting them into OUs to then organise GPM "properly"? Is using OUs and GPMs the recommended way to go with respect to applying policies to groups of users? (I've been using security groups) Edited June 18, 2012 by Gongalong
ricki Posted June 18, 2012 Posted June 18, 2012 A folder in active directory in users and computers is called a OU. Group policies are placed in ou's to apply settings to the objects in the ou. This might be computer or users. Richard 2
Davit2005 Posted June 18, 2012 Posted June 18, 2012 Shared folders are different than OU's, you apply Group Policies to OU's. What server OS have you got. With AD you can basically create a OU tree structure for Users and Computers i.e. An OU in the Tree for Workstations then OU's within that for Different Buildings, Departments etc. (you can group machines together for printer deployment, application distribution, or specific security requirements) it depends on your network structure, physical layout, requirements etc. 2
Gongalong Posted June 18, 2012 Author Posted June 18, 2012 Sorry folks, I edited the above post while the replies came in. ricki: A shared folder is not an OU, as per Davit2005's post. Part of the confusion here, for me at least. Davit2005: Server 2008 R2 (I did post in the correct forum, honest! ) Perhaps this is a discussion point, but is the recommended approach to use OUs for organisation of users and PCs, particularly where GPs need to be applied? I've inherited this AD, and it's been setup with shared folders (essentially using the default folders for the most part).
themightymrp Posted June 18, 2012 Posted June 18, 2012 Yes, you should be putting users and computers into OU's in some kind of order that mirrors how you want your network to run. You can then apply group policies to these OU's. Example, we have 2 main OU's, one called Network Users, One called Network Machines. All user accounts go in one, computers in the other. Each main OU contains sub OU's such as Admins, Staff, Students. Divide the user accounts across these folders and you can then apply different settings based on what kind of user you have. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now