It was the month-end in the office.
The Accounts team was busy preparing salary sheets, bank statements
These files were sensitive and confidential.
The IT Head walked in and said to the System Administrator:
“From today, USB pen drives must be blocked for the Accounts team.
Salary data should never go outside.”
Sounds simple, right?
The system Administrator quickly applied a USB block policy…
But within 10 minutes, phones started ringing.
HR Team: “I cannot copy interview documents from a USB Pen Drive to my PC!”
SALES Team: “Client data transfer is blocked from a USB Pen Drive to my PC!”
Panic everywhere.
Why did this happen?
Because all Department users were managed under a single flat Active Directory structure, it was impossible to apply the USB Pen Drive Block policy to a particular department.
The USB Pen Drive blocked Policy is applied to all Departments.
There was no separation. No structure. No control.
This is where OU (Organizational Unit) becomes a lifesaver.
An Organizational Unit (OU) is a container object inside Active Directory that is used to organize and manage directory objects in a structured way.
Think of OU as a folder inside your company structure.
OU is used to structure Active Directory.
OU can be created as per department in your company.
We can create a separate OU for IT, HR, Accounts, and the Finance Department.
OU works with Group Policy well. You can apply a group policy to an OU
Without OU, Active Directory becomes messy and unmanageable.
With the OU, the Active Directory becomes structured and manageable.
Let us take the following example
The IT Head walked in and said to the System Administrator:
“From today, USB pen drives must be blocked for the Accounts team.
System Administrator says no worries, we have created department-wise OU in Active Directory
System Administrator then applies the policy to the Account OU only
As a result the USB Pen Drive is blocked for the Account OU only
An Organizational Unit (OU) is a container object inside Active Directory that is used to organize and manage directory objects in a structured way.
🔹 Can OU contain computers?
Yes, users, computers, and groups.
Yes, OU is mainly used for GPO application.
No, OU is inside a domain.
Yes, OUs can be created inside OUs.
Domain Admin, Enterprise Admin or delegated admin.
Logical only.
Many companies worldwide use Microsoft technology.
It is common for hiring managers and recruiters to look for system administrators/system engineers who are familiar with Microsoft servers.
With Attari Classes' live instructor-led sessions, you can master various aspects of Microsoft Servers and implement, manage, create, deploy, and troubleshoot them.
You will learn skills like Active Directory, DNS, Group Policy, NTFS permissions, OU management, Site Subnets, Replication, DFS, DHCP, IIS, ADCS, PowerShell, FSMO roles and much more.
The course also covers hybrid technologies, including Azure Entra ID Sync, Azure File Sync, Azure Update Manager, and Azure Hybrid Backup, giving you the expertise to integrate and manage hybrid infrastructures with confidence.
Enrol in this Windows Server Hybrid course today and take your career to the next level.
|
DATE
|
SCHEDULE
|
TIME
|
|
26th JULY
|
SAT & SUN (5 WEEKS)Upcoming Weekend Batch
|
1:30 PM to 5:30 PM (IST)
|
|
20th JUNE
|
SAT & SUN (5 WEEKS)Batch Started
|
8:00 AM to 12:00 PM (IST)
|
|
24*7
|
Self Paced Learning Live
Recorded Lectures
|