Organizational Units are fundamental for delegating control, applying group policies, and organizing resources in Active Directory. Therefore, proper management of OUs is crucial for maintaining security, efficiency, and compliance. By effectively managing OUs, admins can create a more secure and streamlined Active Directory environment.
- Launch the Active Directory Users and Computers console.
- Right-click the domain name and select New »Organizational Unit.
- Enter a name for the OU and click OK to create the OU in your Active Directory environment.
Note: By default, the Protect object from accidental deletion is enabled for OU. You can disable it if you do not require protection for the OU.
- Right-click the organizational unit you want to delete in the Active Directory.
- Select Delete from the context menu and click Yes to confirm the deletion.
- Right-click the organizational unit (OU) you want to move.
- Click Move…, select the new parent OU or container, and then click OK.
Apply Group Policy Objects to an Organizational UnitIn a dynamic organization, not all users or devices require the same policies. Applying Group Policy Objects to OUs allows you to address the unique needs of specific groups without disrupting others in your Active Directory.
- Open Server Manager and navigate to Tools»Group Policy Management console.
- Right-click the desired OU where you want to link the GPO.
- Select Link an Existing GPO, choose the GPO you want to link, and click OK.
- Right-click the OU and choose Create a GPO in this domain,and Link it here….
- Enter a name for the new GPO and click OK.
- Right-click the newly created GPO (linked to the OU) and select Edit to configure the GPO settings.
- In the Group Policy Management Editor, configure the GPO settings according to your requirements.
Note: By default, organizational units inherit GPOs from their parent OUs. To prevent this, right-click the OU in Group Policy Management and select Block Inheritance.
Never Miss a Change in AD OUs: Track, Analyze, and Act Instantly with AdminDroid!
The all organizational unit activities report helps you track all changes in Active Directory organizational units, such as creations, deletions, movement, and more. It provides key details such as when and where the change occurred, who made it, and where it was logged.
Meanwhile, the GPO assignments across OUs report offers detailed insights into GPOs linked to organizational units with information such as the OU display name, GPOs linked to it, inheritance status, and more.