Windows Server Note (vi): Active directory Domain Services: organizational unit

Source: Internet
Author: User

An organizational unit (Organization Unit,ou) is a container in Active Directory that groups objects in a domain into a logical group that can contain: users, groups, computers, and other OUs, as shown, but not limited to, as shown; OUs can only contain objects in their own domain. Also, the nesting of OUs (OUs below the OU) is not recommended to be more than 10 layers;

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/49/88/wKioL1QUQpjC_5zVAABCdANWxu4654.png "title=" capture. PNG "alt=" Wkiol1quqpjc_5zvaabcdanwxu4654.png "/>


OUs are typically based on management requirements and will be managed together with objects that have the same attributes (same department, same group, and so on). The default container, other than domain controllers, does not belong to the OU;

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/49/8B/wKioL1QUT2HjfR6WAACi0vIyr8s386.png "title=" A.png " alt= "Wkiol1qut2hjfr6waaci0viyr8s386.png"/>


First, create an organizational unit:

1. Open Active Directory Users and Computers, right click on the server (domain name), select "New"-"organizational unit";

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/49/8B/wKioL1QUUOvRY14NAAE2kSIdHew966.png "title=" Capture 1. PNG "alt=" Wkiol1quuovry14naae2ksidhew966.png "/>


2, in the Name field to enter the organizational unit name, I am building here is called it organization unit, tick "prevent container accidentally deleted", select "OK";

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/49/8B/wKioL1QUUUqCZ_x5AAAyrH46jCA862.png "title=" Capture 2. PNG "alt=" Wkiol1quuuqcz_x5aaayrh46jca862.png "/>


3, it is called the organizational unit is created well;

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/49/8B/wKioL1QUUeGTKNA6AACbYN41LYs162.png "title=" Capture 2a.png "alt=" Wkiol1quuegtkna6aacbyn41lys162.png "/>


Second, delete the organizational unit:

1, the previous creation of the OU, we said to check the "Prevent accidental deletion of containers", then we directly delete the OU after checking, we will find that you do not have sufficient permissions, so we have to delete the OU, we have to go to the "Prevent accidental deletion of containers" before the tick off;

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/49/8A/wKiom1QUUZCh1HjoAAApRJXFyno787.png "title=" Capture 3. PNG "alt=" Wkiom1quuzch1hjoaaaprjxfyno787.png "/>


2. Open Active Directory Users and Computers and select "View-Advanced Features";

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/49/95/wKioL1QVh6ygZmWiAACKP_v8jE4576.png "title=" Capture 4. PNG "alt=" Wkiol1qvh6ygzmwiaackp_v8je4576.png "/>


3. Right-click the OU you want to delete, select "Properties";

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/49/94/wKiom1QVh9uwVecaAADyBusr7bA939.png "title=" Capture 5. PNG "alt=" Wkiom1qvh9uwvecaaadybusr7ba939.png "/>


4, select "Object", the following "Prevent accidental deletion of objects" before the tick off, and then "OK", and then right-click the OU you want to delete, now delete can be deleted;

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/49/95/wKioL1QViCqAKqr5AABVenecRQI219.png "title=" Capture 6. PNG "alt=" Wkiol1qvicqakqr5aabvenecrqi219.png "/>


Third, mobile organizational unit:

1, we can move the organizational unit by the way of direct drag, in the popup dialog box is selected;

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/49/95/wKioL1QViHLir_a0AABUKefVSfs090.png "title=" Capture 7. PNG "alt=" Wkiol1qvihlir_a0aabukefvsfs090.png "/>


2, but if the direct drag, will appear the following error, it is because "to prevent accidental deletion of objects" before the tick is still in, to the front of the hook removed before you can move, the same way as above;

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/49/94/wKiom1QViSOwAfL3AAAcb1wQlPE590.png "title=" Capture 8. PNG "alt=" Wkiom1qvisowafl3aaacb1wqlpe590.png "/>


Iv. Delegation of authority:

1. Right-click the organizational unit that needs to be delegated, select "Delegate Control";

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/49/94/wKiom1QVidKSadCoAACvcpTAAS0351.png "title=" capture 10. PNG "alt=" Wkiom1qvidksadcoaacvcptaas0351.png "/>


2, select "Next";

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/49/94/wKiom1QVikzCNmYhAADVWHUnMpM462.png "title=" Capture 11. PNG "alt=" Wkiom1qvikzcnmyhaadvwhunmpm462.png "/>


3. Select "Add" to add the users who need to be delegated;

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/49/94/wKiom1QVip7DDkqpAABMZLMQHWM920.png "title=" capture 12. PNG "alt=" Wkiom1qvip7ddkqpaabmzlmqhwm920.png "/>


4, enter the user name, select "Check Name", if the name is correct, there will be an underscore below the user name, of course, you can also choose "advanced" search to find users;

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/49/95/wKioL1QViuaz4I8UAABD2EjeTh8078.png "title=" Capture 13. PNG "alt=" Wkiol1qviuaz4i8uaabd2ejeth8078.png "/>


5, select "Next";

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/49/94/wKiom1QViz2DMbBfAABMkt00ivo221.png "title=" Capture 14. PNG "alt=" Wkiom1qviz2dmbbfaabmkt00ivo221.png "/>


6, select the delegated task, if you choose to "delegate the following common Tasks", the following is the task can be delegated, I have chosen a "create, delete and manage user accounts", of course you can choose more, and then select the next, if you choose "Create custom Task delegation" see 8th step;

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/49/95/wKioL1QVi2_RLp3DAACEq1vCRR0931.png "title=" Capture 15. PNG "alt=" Wkiol1qvi2_rlp3daaceq1vcrr0931.png "/>


7, select "Complete";

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/49/95/wKioL1QVjAfDjMXRAAD1S8RYSDE069.png "title=" capture 16. PNG "alt=" Wkiol1qvjafdjmxraad1s8rysde069.png "/>


8. If "Create custom task delegation" is selected;

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/49/94/wKiom1QVjBPg7G9VAACBNfnWBsk866.png "title=" capture 17. PNG "alt=" Wkiom1qvjbpg7g9vaacbnfnwbsk866.png "/>


9, you can specify the detailed object here, and then select "Next";

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/49/95/wKioL1QVjH3zZ16hAACQqfZj_PQ563.png "title=" capture 18. PNG "alt=" Wkiol1qvjh3zz16haacqqfzj_pq563.png "/>


10, set permissions here, select "Next";

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/49/95/wKioL1QVjPmgHsqTAABnrmpx3lE696.png "title=" capture 19. PNG "alt=" Wkiol1qvjpmghsqtaabnrmpx3le696.png "/>


11, select "Complete";

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/49/96/wKioL1QVjYjDWVoYAADoHxmFbB4955.png "title=" capture 20. PNG "alt=" Wkiol1qvjyjdwvoyaadohxmfbb4955.png "/>

This article is from the "Snow Orchid" blog, please be sure to keep this source http://yupeizhi.blog.51cto.com/3157367/1552619

Windows Server Note (vi): Active directory Domain Services: organizational unit

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.