Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Hi folks,

 

Am I right in thinking that OUs within group policies are completely separate from OUs within AD?

 

If so, why create OUs within the GP editor?

 

And how do OUs within the GP editor affect the priority in which GPOs are applied?

 

Sorry, I'm confused!

 

TIA

Posted

1. They are the same

2. N/A

3. The lower down the OU the higher priority will the setting be. If you set enabled on a setting in an ou but on the same setting on a sub ou you selected disabled it will apply the sub ou settings.

  • Thanks 1
Posted

Ahhh, I inherited this system (already mostly setup), and my server knowledge is a bit rusty. I had assumed that if a container was created within AD it was essentially an OU by default.

 

Presumably everything within AD is a container then, because nothing is replicated in GPM.

Posted (edited)

Presumably a container is described as a "shared folder" in AD?

 

Would there be any dangers of taking users/computers from shared folders and putting them into OUs to then organise GPM "properly"?

 

Is using OUs and GPMs the recommended way to go with respect to applying policies to groups of users? (I've been using security groups)

Edited by Gongalong
Posted

A folder in active directory in users and computers is called a OU.

 

Group policies are placed in ou's to apply settings to the objects in the ou. This might be computer or users.

 

Richard

  • Thanks 2
Posted

Shared folders are different than OU's, you apply Group Policies to OU's.

 

What server OS have you got. With AD you can basically create a OU tree structure for Users and Computers i.e. An OU in the Tree for Workstations then OU's within that for Different Buildings, Departments etc. (you can group machines together for printer deployment, application distribution, or specific security requirements) it depends on your network structure, physical layout, requirements etc.

  • Thanks 2
Posted

Sorry folks, I edited the above post while the replies came in.

 

ricki: A shared folder is not an OU, as per Davit2005's post. Part of the confusion here, for me at least.

 

Davit2005: Server 2008 R2 (I did post in the correct forum, honest! :))

 

Perhaps this is a discussion point, but is the recommended approach to use OUs for organisation of users and PCs, particularly where GPs need to be applied? I've inherited this AD, and it's been setup with shared folders (essentially using the default folders for the most part).

Posted

Yes, you should be putting users and computers into OU's in some kind of order that mirrors how you want your network to run. You can then apply group policies to these OU's.

 

Example, we have 2 main OU's, one called Network Users, One called Network Machines. All user accounts go in one, computers in the other. Each main OU contains sub OU's such as Admins, Staff, Students. Divide the user accounts across these folders and you can then apply different settings based on what kind of user you have.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...