Solved

If you move an OU (and all sub OU's) will it loose any info (e.g., gpo's, etc)?

Posted on 2009-04-05
3
312 Views
Last Modified: 2012-05-06
I want to move an OU within Active Directory.  I will be moving the OU higher in the hierarchy.  Will that cause my OU (and sub OU's) to loose anything?
0
Comment
Question by:victor2008
  • 2
3 Comments
 
LVL 18

Accepted Solution

by:
Americom earned 125 total points
ID: 24074345
Yes, it will lose the GPOs linked to the OU and sub OUs. It also could lose some of the permissions that were assigned through delegation or from direct assignment to the OUs. Also, if you have block inhertance of GPO from parent OU or domains level etc, you could lose that as well. When you move to other OU, you could inherited GPO and permisisions in the similar fasion where you intend to move it to.
0
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 125 total points
ID: 24074671
The GPOs linked directly to that OU should still be linked to the OU when you move it (just tested it).  Americom is right about the GPOs linked at the parent you will lose those
You can also use Group Policy modeling from GPMC to see what policies will apply to a user or computer that is moved before you move them.  In this case you are moving an OU so not as helpful but something to put out there for the future
More on that here:
http://technet.microsoft.com/en-us/library/cc780305.aspx
 
Thanks
Mike
 
0
 
LVL 18

Expert Comment

by:Americom
ID: 24077001
Good point Mike. The GPOs linked "directly" to the OU should still be linked to the OU as those are GPO links which should follow the OU that was linked to.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Join & Write a Comment

[b]Ok so now I will show you how to add a user name to the description at login. [/b] First connect to your DC (Domain Controller / Active Directory Server) SET PERMISSIONS FOR SCRIPT TO UPDATE COMPUTER DESCRIPTION TO USERNAME 1. Open Active …
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now