Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Correct way to setup Active Directory

Status
Not open for further replies.

lilcam

MIS
Apr 22, 2002
52
US
I've always created users and placed them in the default "Users" container. We have over 300 student accounts and about 40 staff/faculty members. Should I create a 'User' and 'Faculty' OU? What advantage does this hold over the regular 'Users' container that I've been creating users in.

Also, I read somewhere that I should create individual computer accuonts first before I join them to the domain. How will this change anything if I wre to just add the computers later. Should I create a new OU for computer accounts or should I just use Windows default container?
 
The benefit you receive from setting up separate containers is management of those users. You will also be able to assign group policy to a container as you cannot do that with individual users.
 
Ok ... makes sense, and here's another question.

I can't get the computer configuration settings to apply to computers. I wanted to disable showing last user logged in name. So I enabled that feature and the PC that I am testing still shows the last user logged in. I also enabled the option to remove the shutdown button from the CTRL-ALT-DEL screen but it still shows up.

However, I can enable both option in the local security settings of the workstation!!! I dont want to have to do this to all workstations!


 
If you are applying your group policy object to an ou, then move all of the computer accounts from the computers container into the group policy your using.
 
Ok ... so i moved the computer accounts into the 'Faculty' OU. There's a GPO called 'Faculty's GPO.' Under the security tab I have the following:

Authenticated Users - READ
Domain Admin - READ,WRITE,DELETE,CREATE
Enterprise Admin - Same as above
Faculty - READ + APPLY

'Faculty' is the name of the group where all faculty members are placed in.

So, if I place ALL computer accounts into this OU, they will be affected by the GPO assigned to this OU?

 
That is correct, they will assume the GPO assigned to the OU.
 
Ok ... did that, but the remove shutdown button from screen is still available. grrrrr
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top