Domains vs. organizational units in Active Directory

James Michael Stewart, Contributor


Domains vs. organizational units
James Michael Stewart

Forests, trees, sites, domains and organizational units are all organizational containers used by Windows 2000 and Windows .NET based Active Directory networks. Forests are used to group one or more trees under a common schema and global catalog. Trees are used to group domains into contiguous DNS name spaces. Sites are used to group domain controllers based on their link speeds and to control AD replication. Domains and OUs are employed to group computers, users and groups for security, delegation and administrative purposes. Group policy objects (GPOs) can be defined for domains as well as OUs.

The difference between a domain and an OU may initially seem slight, but it is very important. Deciding whether to use a domain or an OU should take place in the early planning stages of a network, long before deployment is started. Domains should be employed to group computers, users and groups based on stable business configurations, such as geography. It is not a good idea to use domains to define transient designations, such as function or department. OUs on the other hand are much more flexible than domains. OUs can be used to define stable business configurations, such as geography, but can also be used for more transient designations. Generally, build layers of OUs from general to specific, geography before department, and department before function.

OUs are flexible enough

Requires Free Membership to View

to be moved, grafted and changed as the business organization changes. Manipulating domains is a much more complex process and should be avoided whenever possible. With proper planning and management, multiple layers of OUs can effectively organize and control your network while offering the flexibility to adjust to your company as it grows and changes.

James Michael Stewart is a researcher and writer for Lanwrights, Inc.

This was first published in March 2002

There are Comments. Add yours.

TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to:

Disclaimer: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.