Learn how to a build a cloud-first strategyRegister Now


Active Directory - "Users" Container vs "Organizational Unit"

Posted on 2008-11-18
Medium Priority
1 Endorsement
Last Modified: 2012-05-05
I'm a little confused between an OU an the default "Users Folder" which is displayed under Active Directory on Windows 2003 Server.  

As far as I can tell, the "Users" folder is not an OU - but a container.  I need some succinct clarification on this point.

The reason I'm asking this is that I see that there are various subfolders under 'USERS', but I am unable to create any new ones.  This is probably because I only have view access, so I double checked this by working on my test envionrment which I have DOMAIN ADMIN access to and I am unable to create a sub-folder or sub-container there either.  Furthermore, I am unable to move a branch from else in the OU...I just get an error stating that I cannot move the object because the parent is not a possible superior.

How can I create a sub folder/container under the Users container (and am I using the correct terminology here)?

Question by:drewberrylicious
LVL 20

Accepted Solution

MightySW earned 2000 total points
ID: 22990977
Containers are considered builtin objects and cannot be altered without altering the AD schema.  Ideally you would not use this container but create as MANY OU's as you want (in an organized structure) and emulate what you want\need for now and for the future.  This is why OU's can be created and manipulated.  You need structure and the builtins just give an out of the box structure and builtin groups/users like administrator, guest, IIS anonymous users, etc...

An OU is the same thing as a container, but an OU can have group policies, other OU's, permissions, delegates, etc...  Containers are limited to what you see is what you get.


Author Closing Comment

ID: 31518087
Thanks for the fast and succinct answer.

Expert Comment

ID: 23577876
MightySW is right but you can create subfolders and assign group policy t "USERS" Container..

Refer http://support.microsoft.com/?id=324949 and http://support.microsoft.com/kb/555573

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question