Re: AD setup questions
From: Derek Melber [MVP] (derekm_at_braincore.net)
Date: 04/24/04
- Previous message: Juan: "Re: AD setup questions"
- In reply to: Brian Henry: "AD setup questions"
- Next in thread: Brian Henry: "Re: AD setup questions"
- Reply: Brian Henry: "Re: AD setup questions"
- Messages sorted by: [ date ] [ thread ]
Date: Fri, 23 Apr 2004 21:11:33 -0700
Brian,
You may not find the exact document that you are looking for. If you do, it
will be a lot of reading:-).
Here are two basic rules for AD/OU design:
1) Design OUs for GPO application to both user and computer accounts
2) Design OUs for delegation of administration of user accounts and groups
Now, this might seem simple, but it is complex, yet effective!
Things to keep in mind:
1) GPOs will inherit down to child OUs, so nesting OUs is key
2) the objects down further in the OUs will receive more GPOs (usually) than
those higher, due to the GPOs linked down lower in the OU structure
3) considering #2, usually employees (not execs and IT) will be lower in the
OU structure, having more restrictions. Also, computer accounts for
employees will be lower.
4) consider creating a special separate OU structure for IT/enterprise. You
will place the following objects in here:
IT user accounts, servers, service accounts, IT computer accounts, developer
user accounts, etc.
does this get the wheels cranking at all?
-- Derek Melber BrainCore.Net derekm@braincore.net "Brian Henry" <brianiupmsdn@newsgroups.nospam> wrote in message news:uIbrb%23ZKEHA.3628@TK2MSFTNGP12.phx.gbl... > We are trying to reorganize our AD, is there any articles out there that > you'd consider good to look at on organizeing AD? > > What we want to do is create different group policies and apply them to > different groups, but a user could be in different groups.. I'm kinda > looking for something about something similar to that... I thought makeing > OU's and placeing groups in OU's would do the trick but it appears that the > user objects have to be in the OU's also for that to work and can't be in a > different OU? > >
- Previous message: Juan: "Re: AD setup questions"
- In reply to: Brian Henry: "AD setup questions"
- Next in thread: Brian Henry: "Re: AD setup questions"
- Reply: Brian Henry: "Re: AD setup questions"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|