organising laptops and desktops in AD - best practice

crib bar 531 Reputation points
2023-01-23T11:50:22.9766667+00:00

From a systems administrators perspective, are there any risks in storing both laptop and desktop computers in the same OU, or is it common best practice to store them in their own dedicated OU in your AD domain?
I was trying to understand any logic why AD admins may put each in their own OU, or if its common to group them altogether?

Likewise do you use any specific naming conventions for computers added to AD, to differentiate between desktops and laptops, and if so what benefits does this provide, or if such naming convention wasn't in place, what issues/challenges could this cause?

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
10,619 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,860 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,754 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
333 questions
0 comments No comments
{count} votes

Accepted answer
  1. Limitless Technology 43,941 Reputation points
    2023-01-25T10:47:06.32+00:00

    Hello Crib bar,

    The main reasons to segregate different hardware, such as Desktops and Laptops, is usually the same as to separate Servers and Workstations. For one side, there is the hardware perspective, as you may want to enable some Registry configurations specific for some models. On the other hand, there may be specific GPO that apply to Laptop computers (such as encryption and other policies) that are not required in Desktops. Additionally, there may be additional security policies or application permissions for Laptop users due to mobility (first that comes in mind is to avoid connecting to unencrypted networks, for example)

    Beside that, many sysadmins that are more specific, would create OU per department, and then sub-OU per users or computers, then another OU level for Desktops and Laptops. Depending on the extension and complexity of the organization structure this can be quite an advantage.

    --If the reply is helpful, please Upvote and Accept as answer--

    2 people found this answer helpful.
    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Thameur-BOURBITA 32,511 Reputation points
    2023-01-23T14:31:44.2433333+00:00

    Hi @crib bar

    There are no risk because desktop and laptops are tagged as T2 in tierring administration modele :

    Comprendre le Tiering Model de Microsoft (en français) - Akril.net

    I was trying to understand any logic why AD admins may put each in their own OU, or if its common to group them altogether?

    In an Organozation Unit we can configure :

    • Permission to administrator or group of administrator to manage all objets under this OU
    • Link GPOs

    AD administrators may choose to split OU if the teams who should manage desktop and laptop are not the same.

    The same for GPO. (Regarding the GPO there are many solutions to avoid the slit like security group filtering and wmi filtering)

    Please don't forget to mark helpful asnwer as accepted

    2 people found this answer helpful.
    0 comments No comments

  2. Pavel yannara Mirochnitchenko 11,716 Reputation points
    2023-01-23T12:00:22.1533333+00:00

    I would say, that before the need for divide Desktops and Laptops was bigger, rather than today. You might want to have different Bitlocker and Power options for desktops and laptops.

    In AD for GPO, you could also use wmi filters to outscope desktops from Bitlocker settings, this way you still can use same OU.

    In Intune, you could specify model filters to have different groups for Laptops and Desktops

    Unless desktops play very special role in your organization, (product/factory computers with critical role), I would not bother to divide them at all.

    1 person found this answer helpful.
    0 comments No comments