M
Mikey
I have been wrestling with a couple of issues in regard to the OU
design of our AD structure. I have a pretty good idea about almost all
the OUs, except for the ones that will contain the computer accounts.
I'm hoping some folks will take a look and help me decide which way to
go. Hopefully I can keep this simple.
The OUs I'm pretty certain of will be off the root of the domain and
will be as follows. I'll just use Our to represent the company name.
Our Adminstrators - will contain admin users and computers as well as
Global groups that membership is controlled by admins.
Our Users - will contain all the normal users. If any specific groups
of users need seperation, a sub OU can be created below this one.
Our Resources - will contain OUs for different departments of users.
These OUs will be populated with Global groups for departmental access
to files, printer objects, and share objects.
Our Service Accounts - will contain all service user accounts.
The computer accounts is where I'm uncertain. Here's the layouts I'm
considering...
Domain.com
Our Servers
Application
Corporate
Manufacturing
Database
Corporate
Manufacturing
Our Workstations
Corporate
Manufacturing
Domain.com
Corporate Computers
Servers
Applicaton
Database
Workstations
Manufacturing Computers
Servers
Application
Database
Workstations
Domain.com
Our Computers
Corporate
Servers
Applicaton
Database
Workstations
Manufacturing
Servers
Application
Database
Workstations
I'm really looking to maximize the use of group policy and insure that
the application of the policy layers performs well. I can convince
myself of just about anyone of them. I'm hoping somebody may have some
suggestions or improvements.
Thanks in advance,
Mike
design of our AD structure. I have a pretty good idea about almost all
the OUs, except for the ones that will contain the computer accounts.
I'm hoping some folks will take a look and help me decide which way to
go. Hopefully I can keep this simple.
The OUs I'm pretty certain of will be off the root of the domain and
will be as follows. I'll just use Our to represent the company name.
Our Adminstrators - will contain admin users and computers as well as
Global groups that membership is controlled by admins.
Our Users - will contain all the normal users. If any specific groups
of users need seperation, a sub OU can be created below this one.
Our Resources - will contain OUs for different departments of users.
These OUs will be populated with Global groups for departmental access
to files, printer objects, and share objects.
Our Service Accounts - will contain all service user accounts.
The computer accounts is where I'm uncertain. Here's the layouts I'm
considering...
Domain.com
Our Servers
Application
Corporate
Manufacturing
Database
Corporate
Manufacturing
Our Workstations
Corporate
Manufacturing
Domain.com
Corporate Computers
Servers
Applicaton
Database
Workstations
Manufacturing Computers
Servers
Application
Database
Workstations
Domain.com
Our Computers
Corporate
Servers
Applicaton
Database
Workstations
Manufacturing
Servers
Application
Database
Workstations
I'm really looking to maximize the use of group policy and insure that
the application of the policy layers performs well. I can convince
myself of just about anyone of them. I'm hoping somebody may have some
suggestions or improvements.
Thanks in advance,
Mike