In Active Directory, each domain is responsible for storing and updating its individual domain-directory - which collectively comprise the organization's Active Directory. In addition, a domain is responsible for authenticating access to all resources that are housed in its domain. In reality, these tasks are accomplished by the Domain Controllers - servers that run Active Directory services. These domain controllers are similar to Windows NT's Primary Domain Controllers, although the hardware requirements for Active Directory domain controllers are significantly greater than those of NT. In addition, administering and maintaining an Active Directory domain is substantially more challenging and complex than the older, NT-style domain structure.
Thus, it can be seen that there is considerable overhead involved in running a domain within Active Directory - in administrative, financial and personnel terms. There are also other, significant, network issues that are involved in running a separate domain. IMSS envisions that most groups may wish to avoid investing the time and resources involved in maintaining a separate domain, yet still desire the control and autonomy implied by such a domain. For those groups we recommend they are assigned an Organizational Unit, within the ad.caltech.edu domain.
Organizational Units are conceptually similar to domains, in that they are essentially administrative boundaries. For groups who are assigned an OU, IMSS will delegate complete administrative control of the top-level OU to a defined group of OU Administrators. The OU Administrators will then be able to create users, groups, computers, further OUs etc. within their top-level OU, at their discretion. They can also set rights and access permissions to resources in their OU structure and define Group Policies that apply to their resources. However, these rights and policies will be entirely limited to their OU structure - i.e. a given group of OU Administrators would have no administrative rights to users, groups, computers etc. that existed outside of their OU structure, unless explicitly granted
source
http://www.imss.calt ech.edu/cms.php ?op=wiki&wiki_op=view&id=412
Answered by Smarty
at
3:08 PM on April 23, 2008