Skip to main content

AD DS Users, OUs, & Groups

Users and OUs

Organisational Units - a means of separating users and devices/objects based on location, site, role, job, department

    Sydney OU
      Users Computers Brisbane OU
        Users Computers

          Sales OU
            Users Computers Finance OU
              Users Computers

              • A user account can only be a part of one OU (unlike groups)
              • OUs can be used to handle Group Policy objects - will filter down to OUs below the specified OU
              • Helps to visually separate objects

              Example 1

                Sydney OU
                  Users Computers Brisbane OU
                    Users Computers

                    Example 2

                      Sales OU
                        Users Computers Finance OU
                          Users Computers

                          Groups

                          • Dsitribution Groups (DLs) for Email
                          • Security Groups (Permissions) and Email

                          Group Scopes

                          • Global
                          • Domain Local
                          • Universal

                          Microsoft Strategy

                          • Accounts
                            • Global
                              • Domain Local
                                • Permissions

                          firefox_xlh5XXZiOF.png

                          Universal Groups

                          *For larger organisations multiple globval groups can be linked to a single universal group, which is replicated across all domains

                          firefox_3CAA3dFk5H.png

                          Universal Group Membership Caching Feature

                          • Global Catalog Servers contain a Universal Group List
                          • User Authentication occurs on D.C.s via Kerberos
                          • Kerberos needs to validate with the GCS to identify which groups this user is a member of (via the universal group list)

                          image.png

                          Scenario: users are finding it take a long time to log in - the global catalog server might be located in a different site to where the user and the domain controller are located

                          Solutions

                          • Make the D.C. a Global Catalog server (adds processing overhead)
                          • Universal Group Membership Caching
                            • Every 8 hours (default) domain controller will cache the Universal Group List locally