Skip to main content
AD Academy
Day-to-day administration of AD
Beginner14 minLast updated: Topic 1 of 4

OU, groups and the AGDLP model

How to organize objects and delegate permissions correctly.

Not read

What you will learn here

  • Group types
  • AGDLP — the golden rule
  • How to organize objects and delegate permissions correctly.

An OU () is a logical folder within the domain. It serves two purposes: applying GPOs and delegating administrative permissions ().

Group types

  • Security Group — used for permissions (the one you'll use 99% of the time).
  • Distribution Group — for email distribution lists only.
  • Scope: Local / Global / Universal — determines who can be a member and where the group can be used.

AGDLP — the golden rule

Accounts ← Global group ← Local group ← Permission. In other words: users join a global group by role, the global group joins a local group that represents a resource, and only the local group is actually granted a permission.

New-ADOrganizationalUnit -Name "Finance" -Path "DC=lab,DC=local"
New-ADGroup -Name "G_Finance_Staff" -GroupScope Global -GroupCategory Security -Path "OU=Finance,DC=lab,DC=local"
New-ADGroup -Name "DL_FinanceShare_Modify" -GroupScope DomainLocal -GroupCategory Security -Path "OU=Finance,DC=lab,DC=local"
Add-ADGroupMember -Identity "DL_FinanceShare_Modify" -Members "G_Finance_Staff"
powershell
Architecture and Theory — Under the Hood

The golden rule for permissions: AGDLP — Account → Global Group → Local Group → Permission.

  • Global — members from its domain, used for grouping users.
  • Local — used to grant permission on a resource.
  • Universal — crosses domains, stored in the Global Catalog.
Practical Configuration (PowerShell / GUI)
New-ADOrganizationalUnit -Name "Finance" -Path "DC=corp,DC=com" -ProtectedFromAccidentalDeletion $true
New-ADGroup -Name "GG_Finance" -GroupScope Global -Path "OU=Finance,DC=corp,DC=com"
New-ADGroup -Name "DL_Finance_RW" -GroupScope DomainLocal -Path "OU=Finance,DC=corp,DC=com"
Add-ADGroupMember -Identity DL_Finance_RW -Members GG_Finance
powershell
Real-world organizational scenarios
  • : Granting password reset rights to Helpdesk only for a specific OU, without Admin.

Check yourself

According to the AGDLP model, who is actually granted the permission on the resource?

Was this page helpful?