I present to your attention the optimal structure of Active Directory, which is used by many large companies. Sometimes the number of employees around the world in such companies reaches 10,000 people. Naturally, such large companies use a domain tree divided into countries or continents.

For example:

  • Root domain - heyvaldemar.net
  • Child domain - canada.heyvaldemar.net and ireland.heyvaldemar.net

Moreover, the structure of each domain in the tree is the same.

Optimal Active Directory Structure

The domain structure is divided into cities:

  • Toronto - City of Toronto

Cities are divided into organizational units by objects:

  • Groups - groups
  • Servers - servers
  • Service - accounts to run services
  • Users - user accounts
  • Workstations - workstations

Groups are divided into organizational units according to the scope of the groups:

  • Local - local groups in the domain
  • Global - global groups
  • Universal - universal groups
  • Distribution - distribution groups

Servers are divided into organizational units by service:

  • Disabled - disabled and decommissioned servers
  • Exchange - servers on which Exchange Server is deployed
  • File - servers with shared and confidential network resources
  • Normal - member servers that do not require separation by services
  • Print - servers with shared printers

And so on, depending on the need to separate the servers by services.

Service accounts are divided into organizational units by role:

  • Disabled - disabled service accounts
  • Normal - ordinary service accounts

Users are divided into organizational units by role:

  • Admins - accounts with extended rights
  • Disabled - disabled user accounts
  • External - accounts for contractors and other freelancers
  • Normal - ordinary users who do not require separation by roles

And so on, depending on the need to divide users by roles.

Workstations are divided into organizational units based on user roles:

  • Admins - workstations that use accounts with extended rights
  • Disabled - disabled and decommissioned workstations
  • Normal - ordinary workstations that do not require separation by user roles

My Courses

🎓 Dive into my comprehensive IT courses designed for enthusiasts and professionals alike. Whether you’re looking to master Docker, conquer Kubernetes, or advance your DevOps skills, my courses provide a structured pathway to enhancing your technical prowess.

My Services

💼 Take a look at my service catalog and find out how we can make your technological life better. Whether it’s increasing the efficiency of your IT infrastructure, advancing your career, or expanding your technological horizons — I’m here to help you achieve your goals. From DevOps transformations to building gaming computers — let’s make your technology unparalleled!

Refill My Coffee Supplies

💖 PayPal
🏆 Patreon
💎 GitHub
🥤 BuyMeaCoffee
🍪 Ko-fi

Follow Me

🎬 YouTube
🐦 Twitter
🎨 Instagram
🐘 Mastodon
🧵 Threads
🎸 Facebook
🧊 Bluesky
🎥 TikTok
🐈 GitHub

Is this content AI-generated?

Nope! Each article is crafted by me, fueled by a deep passion for Docker and decades of IT expertise. While I employ AI to refine the grammar—ensuring the technical details are conveyed clearly—the insights, strategies, and guidance are purely my own. This approach may occasionally activate AI detectors, but you can be certain that the underlying knowledge and experiences are authentically mine.

Vladimir Mikhalev
I’m Vladimir Mikhalev, the Docker Captain, but my friends can call me Valdemar.

DevOps Community

hey 👋 If you have questions about installation or configuration, then ask me and members of our community: