No announcement yet.

Groups in 2008R2

  • Filter
  • Time
  • Show
Clear All
new posts

  • Groups in 2008R2

    I have been watching some VTC training on Groups. It has forced me to ask this questions again. Setting up a new domain using 2008R2 and I think I have the groups roles defined. The older server has OU's like so:
    See how everything is in one OU - this means the DC is not in the OU. Would you say this is good organization or not? Will it affect GP on a 2008 Server? What is the simplest option? Thanks for your help - it's invaluable.
    Last edited by pksupport; 29th April 2010, 04:40.

  • #2
    Re: Groups in 2008R2

    Since AD first appeared, DCs have always been in an OU of their own. This allows them to have stricter policies than member computers.

    As far as the groups go, it really doesnt matter where you put them as they are not directly affected by Group Policy (yes, I know it doesnt make sense, but no-one calls it OU Policy )

    I tend to put them close to the users they contain (so under different OUs) but others do as you have done and put them in an OU of their own
    Tom Jones
    MCT, MCSE (2000:Security & 2003), MCSA:Security & Messaging, MCDBA, MCDST, MCITP(EA, EMA, SA, EDA, ES, CS), MCTS, MCP, Sec+
    IT Trainer / Consultant
    Ossian Ltd

    ** Remember to give credit where credit is due and leave reputation points where appropriate **