Creating AD OU structure for GP deployment



Hi there,
I'm looking at implementing group policies for both security and to
deploy/maintain software in a small business (~600 users) with 3 sites.

I've read through all the material I can find however I haven't found if
there is a dis-advantage to creating nested OUs?

For the group policy setup, I'd like to have "Group Policies" being the top
level OU, with "Software", "Security" and "Features" being the three sub-OUs
In these three OUs i'd create security groups i.e. "ApplicationName" with
people from the "Users" and "Security Groups" and link them to group policies
on that level.

i.e
I'd have a group policy for deploying an application "ApplicationName"
defined in the nested OU [Domain] -> [Group Policies] -> [Software] linked
to the security group [Domain] -> [Group Policies] -> [Software] ->
[ApplicationName] which has users and groups from [Domain] -> [Users] and
[Domain] -> [Security Groups]

If I haven't confused everyone already and there is no issues with nesting
OUs, could we also re-create the default Users OU to be the top level with
the 3 site locations underneath?

If we could, we could potentially do the same with the Computers group and
end up with this structure...

Computers
-> Users (End-user machines)
-> Domain Controllers (DCs)
-> Member Servers (Servers)

Users
-> Location0
-> Location1
-> Locatoin2
-> Mailboxes (users created just for their mailboxes... i know... don't
ask...)

Groups
-> Security groups (folder access)
-> Distribution groups (mail)

Group Policies
-> Security Policies (Security group policies)
-> User Policies (Group policies that apply to users)
-> Computer Policies (Group policies that apply to computers)
-> Software Policies (Software deployment policies)
-> Feature Policies (Features such as disabled screen saver which aren't
quite security)

This way, while its slightly more complex, we can implement group policies
from one point in the structure to security groups within each Group Policy
OU and simply add/remove users/computers from the group to control them.
We do get duplication (sort of) in the form of a policy like the following...

The member of [Domain] -> [Group Policies] (OU) -> [Computer Policies] (OU)
-> [Member Services Policy] (Security Group) would be [Domain] -> [Computers]
(OU) -> [Member Servers] (OU)

Hope this makes some sense and I'm heading in the right direction!
Sorry for such a complicated question and thanks for any help you can give me.
Cheers,
Jason
.



Relevant Pages

  • Re: RE: web browsing in production environment - a journey through comfort and security
    ... I would hold yourself to keep group policies on for one good reason. ... could we rely our security on such proxy servers instead ... Securing Apache Web Server with thawte Digital Certificate ...
    (Security-Basics)
  • RE: Active Directory network security
    ... AD's group policies can be used to keep AD itself pretty secure, ... down tightly for security within AD, but a rogue laptop that is not a domain ... When Microsoft first touted Active Directory they pushed for a Single Forest ... Auditing is also very important - audit changes in domain admin groups, ...
    (Focus-Microsoft)
  • Re: Creating AD OU structure for GP deployment
    ... I'm looking at implementing group policies for both security and to deploy/maintain software in a small business with 3 sites. ... Um, I'd only consider myself intermediate as far as skill level with ADS but I've never heard of creating OUs for software, security and features. ... GPOs don't apply to containers, only to GPOs and to the domain/site level. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Creating AD OU structure for GP deployment
    ... For the group policy setup, I'd like to have "Group Policies" being the top ... but I've never heard of creating OUs for software, security and features. ... only to GPOs and to the domain/site level. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Active Directory design
    ... I've found that group policies tend to be created out of necessity rather ... implemented at the domain level as you are planning. ... default domain policy to define a small number of domain-wide settings ... If I go for the OU deployment scenario, do I need to place the Security ...
    (microsoft.public.win2000.active_directory)