1 00:00:06,430 --> 00:00:10,680 When you first implemented it yes there is only one O U. 2 00:00:10,750 --> 00:00:12,510 The domain controllers. 3 00:00:12,520 --> 00:00:19,720 Oh you you must create any other o use you can create organizational units by using graphical tools 4 00:00:19,720 --> 00:00:22,150 such as Active Directory. 5 00:00:22,150 --> 00:00:27,850 Use our recent computers or Active Directory administrative center. 6 00:00:27,850 --> 00:00:35,750 You can also create organizational units by using command line tools such as Windows power cell. 7 00:00:35,770 --> 00:00:40,580 You must create all new or used by using an administrative tool. 8 00:00:40,600 --> 00:00:46,300 There is no mechanism to copy existing or use to create new ones. 9 00:00:46,300 --> 00:00:54,100 Also consider accidental deletion accidental deletion is one of the major causes of Active Directory 10 00:00:54,100 --> 00:00:55,240 recoveries. 11 00:00:55,240 --> 00:01:06,220 Therefore Windows Server 2016 supports the protect o use from accidental deletion feature so organizational 12 00:01:06,220 --> 00:01:14,610 units have protection from accidental deletion share of the following benefits one administrators can 13 00:01:14,610 --> 00:01:23,170 not accidentally delete or use if they want to delete an oh you intentionally they must remove the protection 14 00:01:23,470 --> 00:01:25,560 prior to delete it they owe you. 15 00:01:25,690 --> 00:01:34,810 Second administrators cannot accidentally move or use and third or use that you have newly created by 16 00:01:34,810 --> 00:01:40,050 use an active directory administrative center or Active Directory. 17 00:01:40,140 --> 00:01:49,420 Users and Computers and Windows Server 2000 8 or newer have automatic protection against accidental 18 00:01:49,420 --> 00:01:50,420 deletion. 19 00:01:50,440 --> 00:01:57,820 You can enable or disable the protection from accidental deletion in Active Directory administrative 20 00:01:57,820 --> 00:02:02,440 center in the proper text dialog box of the O. 21 00:02:02,460 --> 00:02:11,140 You can also use Active Directory Users and Computers to enable or disable the protection from accidental 22 00:02:11,140 --> 00:02:17,010 deletion on the object tab and the O you properties dialog box. 23 00:02:17,020 --> 00:02:24,010 Please note that you must enable the advanced view in Active Directory user and computers before you 24 00:02:24,010 --> 00:02:29,550 can see the object tab in the all you properties dialog box. 25 00:02:29,560 --> 00:02:35,190 You can also use Windows power shell to enable or disable protection. 26 00:02:35,200 --> 00:02:43,090 For example you can search for or use that are not protected and enable protection with the following 27 00:02:43,090 --> 00:02:44,050 command. 28 00:02:44,050 --> 00:02:54,940 Get a organizational unit filter asterisk properties protected from accidental deletion by there. 29 00:02:55,030 --> 00:03:03,430 Find all the objects with the following property protected from accidental deletion equal into false 30 00:03:03,790 --> 00:03:12,670 and then set the results to send the results to set organizational unit was protected from accidental 31 00:03:12,670 --> 00:03:17,370 deletion parameter switched on or recoil into Drew. 32 00:03:17,380 --> 00:03:22,790 This will find told that objects and to enable the protection. 33 00:03:22,790 --> 00:03:30,460 Some words about moving objects between 0 use as job role changes or computers are reassigned. 34 00:03:30,460 --> 00:03:36,820 You will need to move objects and edit s to different or use moving objects between 0 using the same 35 00:03:36,820 --> 00:03:44,380 domain is a simple task you can right click the object and select move and then select the new location. 36 00:03:44,380 --> 00:03:52,690 Or you can click and drag the object to the new or you moving objects have the fallen effects on the 37 00:03:52,690 --> 00:04:00,850 objects permissions permissions assigned directly to the object remain in place after the object moves 38 00:04:01,090 --> 00:04:08,770 and the object will inherit new permissions from its new or you and will loose an inherited permissions 39 00:04:08,770 --> 00:04:10,230 from the from the previous. 40 00:04:10,230 --> 00:04:18,550 So you the following permissions are required to move to the s object duly child permission on the source 41 00:04:18,650 --> 00:04:26,620 or or you or delete permission of the object that you are more than you'll also need right proper permission 42 00:04:26,620 --> 00:04:34,150 on the object for the relative distributed name distinguished name and common name and you'll. 43 00:04:34,160 --> 00:04:37,690 Create child permission on the target all you.