Containers vs. OUs
When you open the Active Directory Users and Computers (ADUC) Microsoft Management Console (MMC) with the advanced view, there will be pre-setup folders.
But not all of these are OUs. They are mostly containers:
Figure 9.3: Containers and OUs
The only default OU in the AD environment is the Domain Controllers
OU. All other folders in the tree are containers. Containers can also contain objects. The Computers
and Users
containers are good examples of that. By default, any computer object will be stored in the Computers
container. All of the default user accounts and security groups are stored in the Users
container. Similar to OUs, containers can also be used to delegate administrative control. The only difference between containers and OUs is that group policies cannot apply to containers. Group policies can be assigned only to OUs. The system also does not allow you to create new containers other than the containers that are created by the system...