Creating a new OU within IFAS Return to IT/SA Services Documentation: Active Directory |
Instructions for when a new People OU is created and a corresponding Department OU is then needed:
Note...you will need to be a member of the . IFAS AD ADMINS Group to perform these steps.
- Copy Description of OU from the People OU
- Create OU in ad.ufl.edu/UF/Departments/IFAS/-Central-IT/Groups/Admin Groups
- Create . IFAS-ADMN-OU Group
- Create . IFAS-ADML-OU Group
- Create . IFAS-ADM-OU Group
- Add . IFAS-ADMN-OU group to the "Members" tab of . IFAS-ADM-OU
- Add . IFAS-ADML-OU group to the "Members" tab of . IFAS-ADM-OU
- Add . IFAS-ADM-ALL group to the "Member Of" tab of . IFAS-ADM-OU
- Add . IFAS-ADM-CO-MANAGED or . IFAS-ADM-UNIT-MANAGED group to the "Member Of" tab of . IFAS-ADM-OU
- Add . IFAS-ADML-CO-MANAGED or . IFAS-ADM-UNIT-MANAGED group to the "Members" tab of IF-ADML-OU
- Add . IFAS-ADML-ALL group to the "Member Of" tab of IF-ADML-OU
- Add . IFAS-ADMN-CO-MANAGED or . IFAS-ADMN-UNIT-MANAGED group to the "Members" tab of IF-ADMN-OU
- Add . IFAS-ADMN-ALL group to the "Member Of" tab of IF-ADMN-OU
- Delegate Control of the OU
- Select the group IF-ADMN-OU
- Select Create a custom task to delegate
- Select this folder, existing objects in this folder, and creation of new objects in this folder
- Select everything but full control
- Delegate Control of the OU
- Select the group IF-ADMN-OU
- Select Create, delete and manage user accounts
- Create OU in \\UFDC01\IFAS-SCRIPTS
- Give . IFAS-ADMN-OU Modify permissions
- Create a GPO
- Open Group Policy Management Console
- Select Create and Link a GPO
- Name it IF-OU Computer
- Right Click and select edit
- Expand Windows Settings
- Expand Security Settings
- Expand Restricted Groups
- Add Group
- Type UFAD\IF-ADM-OU
- Click add under this group is a member of:
- Type Administrators
- Click OK
The new OU should now be properly configured.
|