A Microsoft Active Directory domain container that can hold users, groups, and computers is an organizational unit (OU). It is the smallest unit to which a Windows system administrator can assign a Group Policy setting or account permission. An organizational unit may contain multiple OUs, but each attribute within the containing OU must be distinct.
对象 不能包含来自其他域的 Active Directory 组织单位。以下部分将介绍管理 OU 的基本命令。