An OU () is a logical folder within the domain. It serves two purposes: applying GPOs and delegating administrative permissions ().
Group types
- Security Group — used for permissions (the one you'll use 99% of the time).
- Distribution Group — for email distribution lists only.
- Scope: Local / Global / Universal — determines who can be a member and where the group can be used.
AGDLP — the golden rule
Accounts ← Global group ← Local group ← Permission. In other words: users join a global group by role, the global group joins a local group that represents a resource, and only the local group is actually granted a permission.