Introduction
This article has the steps to use the Active Directory Users and Computers (ADUC) tool to view a managed organizational unit (OU) in Central Services or Hokies Active Directory.
Instructions
An organizational unit (OU) is a container in Active Directory (AD) for storing objects such as accounts, groups, and other OUs. Organizing accounts into OUs allows for easier administration and makes it possible to delegate administrative tasks including Google Workspace storage allotments. Hokies OU admins are assigned users within the Hokies AD that are authorized to administer their OU.
One important idea to keep in mind when using OUs: They are not security principles. This means that they cannot be used to secure resources.
- Click Start.
- Type: admin.
- As you type, results will appear and change. Click Windows Administrative Tools or Administrative Tools.
- Double-click Active Directory Users and Computers.
- Right click on the domain cntrlsrvs.w2k.vt.edu in the left pane.
- Click Change Domain....
- In the Domain: text box, type: cntrlsrvs.w2k.vt.edu.
- Optionally, place a check in the Save this domain setting for the current console check box.
- Click OK.
- Navigate to your OU.
- In the left pane, double-click cntrlsrvs.w2k.vt.edu.
- Double-click Central.
- Click the name of your OU. You can now administer the OU.
- In the left pane, double-click cntrlsrvs.w2k.vt.edu.
How do I create computer accounts in a Central Services OU?
You must be the administrator of your OU in Central Services to perform these actions. These instructions pertain to computer accounts in a Central Services OU.
- Pre-create the computer account.
- On the OU administrator's computer, start the Active Directory Users and Computers administrative tool.
(For instructions on installing the tool, see Installing the Active Directory Users and Computers Tool.) - In the left pane, browse to and click your OU to highlight it.
Example: cntrlsrvs.w2k.vt.edu, Central, ABC (where ABC is replaced with the name of your OU). - In the menu bar, click Action.
- Click New.
- Click Computer.
- In the Computer name: text box, type the name of the computer to be added to the OU.
- Click OK.
- Wait 15 minutes for the computer account to replicate to all domain controllers.
- On the OU administrator's computer, start the Active Directory Users and Computers administrative tool.
- Add the computer to your Central Services OU.
- Log on to the computer you want to join to the OU using a local administrator account.
- Set the computer's DNS addresses to the appropriate addresses.
- Click Start.
- Type: network connections.
- As you type, results will appear and change. Click View network connections.
- Right-click the appropriate connection.
- Click Properties.
- Double-click Internet Protocol Version 4 (TCP/IPv4).
- Click Use the following DNS server addresses:
- In the Preferred DNS server: text box, type: 198.82.162.237.
- In the Alternate DNS server: text box, type: 198.82.174.15.
- Click OK.
- Click OK.
- Close the Network Connections window.
- Change the computer's domain membership to cntrlsrvs.w2k.vt.edu.
- View the system properties.
- Click Start.
- Type: system.
- As you type, results will appear and change. Click System.
- On the right side of the window, click Change settings.
- Change the workgroup and domain membership.
- Click the Computer Name tab.
- Click Change....
- Under Member of, click Domain:.
- In the Domain: text box, type: cntrlsrvs.w2k.vt.edu.
- Click OK.
- In the Windows Security window that prompts for permission to join the domain:
- In the User name text box, type: hokies\ABC.
(Replace ABC with your own Hokies ID.) - In the Password text box, type your Hokies passphrase.
- Click OK.
- In the User name text box, type: hokies\ABC.
- When you see the Welcome to the cntrlsrvs.w2k.vt.edu domain message, click OK.
- **Important: If you see "The following error occurred attempting to join the domain 'cntrlsrvs.w2k.vt.edu': Access is denied", verify that you used the MMC to pre-create the computer account as directed above.**
- Click OK.
- When you see a message saying you have to restart your computer, close all windows, and restart your computer.
- View the system properties.
- The added computer can now be logged on to with a VT username and passphrase.
How do I use ADUC to administer a Central Services managed OU on a computer not in the Central Services AD?
- Ensure that ADUC is installed. See Installing the Active Directory Users and Computers (ADUC) Tool for details.
- In the command below, replace {username} with your Hokies account username.
- Command: runas /user:hokies\{username} /netonly "mmc.exe dsa.msc"
- The "netonly" switch specifies that the credentials you provide are only used for remote access (a user profile should not be created/used on local system).
- You may receive an error message about "Naming information cannot be located". This is expected, and is safe to ignore. Click OK if you received this error message. (The "Active Directory Users and Computers" window will appear anyway, afterwards.)
- In the resulting "Active Directory Users and Computers" window, RIGHT-CLICK Active Directory Users and Computers (the top-most item of the left panel's navigational hierarchy listing) and click Change Domain....
- In the Domain text box, type
- EITHER - "w2k.vt.edu" (to connect to the Hokies domain)
- OR- "cntrlsrvs.w2k.vt.edu" (to connect to Central Services domain)
- Then click OK.
- In the left panel, under Active Directory Users and Computers should now appear a triangle pointing to the name of the domain you specified. Click that triangle to expand the OU structure of the domain.
- Finally, to find your managed OU:
- NOTE: in the wording below, "{ou}" represents your managed OU.
- EITHER- for Hokies OUs: You should be able to click the triangle and browse to "w2k.vt.edu/vt/{ou}" to view and administer your Hokies managed OU.
- OR- for Central Services OUs: You should be able to click the triangle and browse to "cntrlsrvs.w2k.vt.edu/Central/{ou}" to view and administer your Central Services managed OU.
Related Central Services AD Articles
- What is the difference between the Hokies domain and Central Services domain?
- What is an organizational unit in Active Directory?
- How do I become a Central Services organizational unit (OU) admin?
- What is the Active Directory Users and Computers Tool, and how do I install it?
- How do I view a organizational unit in the Active Directory Users and Computers tool?
- How do I create computer accounts in a Central Services organizational unit?
Related Hokies AD Articles
- What is the difference between the Hokies domain and Central Services domain?
- What is an organizational unit in Active Directory?
- What is a Hokies organizational unit admin (OU admin)?
- How do I become a Hokies OU admin?
- How does a Hokies OU admin manage their OU?
- How does a Hokies organizational unit (OU) admin manage their admin group?
- What is the Active Directory Users and Computers Tool, and how do I install it?
- How do I view a organizational unit in the Active Directory Users and Computers tool?