Re: huge user OU
From: Simon Geary (simon_geary_at_hotmail.com)
Date: 06/11/04
- Next message: Ben Blackmore: "Re: Local Security Overriding GP?"
- Previous message: eashwar: "AD import across differenet domains"
- In reply to: Jeff Senter: "Re: huge user OU"
- Next in thread: Eric Chamberlain, CISSP: "Re: huge user OU"
- Messages sorted by: [ date ] [ thread ]
Date: Fri, 11 Jun 2004 08:20:51 +0100
That's an incorrect assumption. They will only be able to apply different Computer settings if they do that. With all the Users in One OU all users will have to get the same User settings, notwithstanding any ACL's and WMI filtering but that would get very messy for a large number of users. Try to group users that will need the same Group Policy into the same OU.
"Jeff Senter" <jsenter@erols.com> wrote in message news:OAUDdB0TEHA.3984@TK2MSFTNGP09.phx.gbl...
Asking around, they are plaing on have around 100 to 150 people with admin rights and somewere between 25 and 200 machine OU that they can apply differant polocies to. They are assuming that they thay can apply GPO to people based on which OU there workstation is in.
Simon Geary wrote:
As a rule of thumb there are two reasons to divide your users into different
OU's. If they will have different Group Policies applied; and if you will
use delegation of administration to allow different users to administer the
accounts.
In your case, if all users will be given the same Group Policies and the
same admins will be responsible for the accounts then there is no problem
having that many users in one OU, although searches will take a little
longer.
The less OU's the better, in my opinion, as it keeps things simple. I don't
think large numbers alone would justify creating more than one OU.
"Jeff Senter" <jsenter@erols.com> wrote in message
news:OgjsOlVTEHA.760@TK2MSFTNGP12.phx.gbl...
I do some consulting for an University and they are planing on haveing
all of the users in one large OU. The plan on breaking the machines up
in to smaller OU. THey belive that thay can manage this thoug GPO
easily with this configuration. SOme thing tells me this is not going
to work well but I can not put my finger on it. Or am I wrong am this
configuration will work just fine.
- Next message: Ben Blackmore: "Re: Local Security Overriding GP?"
- Previous message: eashwar: "AD import across differenet domains"
- In reply to: Jeff Senter: "Re: huge user OU"
- Next in thread: Eric Chamberlain, CISSP: "Re: huge user OU"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|