Improve company productivity with a Business Account.Sign Up

x
?
Solved

Designing an OU structure

Posted on 2004-08-22
5
Medium Priority
?
452 Views
Last Modified: 2010-04-14
What is the best way to design OU's?  I have seen some designs of AD like:

SALES OU
       |_________Users
       |_________Computers

or:


CLIENTS OU
        |__________Sales
        |__________Engineering
        |__________Shipping

or:

CLIENTS OU
       |__________Sales
       |                      |________Users
       |                      |________Computers
       |
       |__________Engineering
                               |________Users
                               |________Computers

                   
The more the OU's get nested the more finer control we can acheive through GPO's.  What are the best practices for OU design?  What do most people do?
0
Comment
Question by:valicon
5 Comments
 
LVL 17

Expert Comment

by:Eagle6990
ID: 11866590
There are some best practices but it all depends on how you run your business.  Are the clients internal users or are they outside clients?  If they are your clients inside the company, I wouldn't use the second or third structure you posted since that becomes a redundant OU to have your clients all grouped since you can just apply a GPO to the whole domain and accomplish the same thing.

In our organization inside an OU we put all of the users just in the OU and then create a sub-OU for the computers.  We probably don't even need that though.  Since you can create a group with users and/or computers in them, then you can still have good control over your OUs by adding or denying the groups to the OU.

I vaguely remember some reason you didn't want a whole bunch of nested OUs, but I can't remember the reason right now.
0
 
LVL 3

Accepted Solution

by:
saito1 earned 1000 total points
ID: 11867715
Hi Valicon,
as you can see below I change sub units to OU. you may need to delegate sub OUs or need to apply different GPOs to each one.
my practical experience says users and computers in an OU must be in different units to control easyly.
and also if you have clients inside and outside then under "Clients OU" you better create "Client_inside OU" and "Clients_outsite OU". and if you have offices in different cities and you better seperate cities by their names like Clients_Atlanta OU, Clients_LosAngeles OU etc. hope this helps...

CLIENTS OU
       |__________Sales OU
       |                      |________Users
       |                      |________Computers
       |
       |__________Engineering OU
       |                       |________Users
       |                       |________Computers
       |
       |__________Shipping OU
                               |________Users
                               |________Computers



CLIENTS OU
  |
  |_ Clients Inside OU
  |       |__________Sales OU
  |       |                      |________Users
  |       |                      |________Computers
  |       |
  |       |__________Engineering OU
  |       |                       |________Users
  |       |                       |________Computers
  |       |
  |       |__________Shipping OU
  |                               |________Users
  |                               |________Computers
  |
  |
  |_ Clients Outsite OU
          |__________Sales OU
          |                      |________Users
          |                      |________Computers
          |
          |__________Engineering OU
          |                       |________Users
          |                       |________Computers
          |
          |__________Shipping OU
                                  |________Users
                                  |________Computers
0
 
LVL 17

Expert Comment

by:Eagle6990
ID: 11870525
In my opinion, users and computers really don't need their own OU since your GPO has separate settings for User configuration and Computer configuration so they could happily coexist in one single OU and the GPO would automatically separate the computers from users.  But it does look nicer to have them all broke out.
0
 
LVL 12

Author Comment

by:valicon
ID: 11908689
Thanks all for the replies. Saito1, I pretty much am designing using the sub OU's.  In my example above the sub units were OU's. Sorry for the confusion. So I am doing the following:


CLIENTS OU
       |__________Sales OU
       |                      |________Users OU
       |                      |________Computers OU
       |
       |__________Engineering OU
       |                       |________Users OU
       |                       |________Computers OU
       |
       |__________Shipping OU
                               |________Users OU
                               |________Computers OU

Thanks for your help :)

0
 
LVL 3

Expert Comment

by:SuperGhosty
ID: 13469653
I read in an O'Reilly book some time ago that having over 12 OU's (I don't remember if it said nested or not) will cause a performance drop in Active Directory. Either way its always best to plan ahead... try to think of every possible scenario and then some when designing your OU Structure. For example if the Accounting OU decides to split into Accounts Receivable and Accounts Payable. I'm sure you already have a plan, just wanted to point that out.
0

Featured Post

The 14th Annual Expert Award Winners

The results are in! Meet the top members of our 2017 Expert Awards. Congratulations to all who qualified!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Article by: Eric
When it comes to building apps, it's more than just writing code. And unfortunately, many people (and companies) forget that. In fact, the raw time it takes to build the app itself is only half the battle.
From store locators to asset tracking and route optimization, learn how leading companies are using Google Maps APIs throughout the customer journey to increase checkout conversions, boost user engagement, and optimize order fulfillment. Powered …
Through the video, you can check the migration process of Outlook PST file to PDF. Kernel for Outlook to PDF tool can convert Outlook emails with all attributes like Subject, To, From, Cc, Bcc and other folders such as Inbox, Outbox, Sent Items, Jun…

606 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question