In Active Directory, there are different types of objects, such as user accounts, groups, and devices. It is important to manage them effectively. Organizational units can group objects that have similar administrative and security requirements within the domain. Organizational units are used to delegate the administration of objects and apply group policies.
OU design changes are less complex compared to domain- and forest-level structure changes. As OUs are bound to group policies, when you change the structure, you need to make sure the correct group policies are still applied. When you move objects from one OU to another, object will inherit the security settings and group polices that are applied to the destination OU. It will not move any settings it has in the source OU level.
The forest owner can delegate permission to users to become OU administrators...