Skip to content

OU design and delegation of control

Design an OU structure around who administers what and which policies apply, keep new objects out of the default containers, and delegate exactly the rights a team needs to a group, documented and reviewable.

Level
Intermediate
Length
About 60 minutes
Contents
3 lessons · final exam
Status
Published · updated 1 Oct 2026

Skills you'll practise

  • Design an OU structure from administration and Group Policy needs rather than the org chart
  • Explain why objects in the default Users and Computers containers can't receive OU-linked GPOs, and redirect new objects with redircmp and redirusr
  • Delegate a specific task on an OU to a group with the Delegation of Control Wizard, granting the least rights that do the job
  • Identify why built-in groups such as Account Operators are a poor substitute for delegation
  • Review and document an OU's delegated permissions so they can be audited and removed

Course outline

  1. 1.Designing OUs for administration and policyLesson · 20 min
  2. 2.Delegation of control: least privilege, to groupsLesson · 22 min
  3. 3.Reviewing, documenting and cleaning up delegationsLesson · 18 min
  4. 4.OU design and delegation of control: knowledge checkKnowledge check · 14 questions
  5. 5."Just put the help desk in Domain Admins"Scenario
  6. 6.Final exam7 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.