Organisational Unit: A part of Active Directory used to Organise and Manage the objects of AD
An organizational unit (OU) is a subdivision within an Active Directory into which you can place users, groups, computers, and other organizational units. You can create organizational units to mirror your organization's functional or business structure. Each domain can implement its own organizational unit hierarchy. If your organization contains several domains, you can create organizational unit structures in each domain that are independent of the structures in the other domains.
The term "organizational unit" is often called as "OU" in casual conversation. "Container" is also often applied in its place, even in Microsoft's own documentation. All terms are considered correct and interchangeable.
10 mllion users.because active directory support 10 million objects if you do not create any OU,Any shared Folder or other object.
The dsmove command-line tool can be used to move an object from one Organizational Unit (OU) to another in Active Directory. This tool allows administrators to specify the source and destination OUs while moving the object.
Tombstone
lingering object
object classes and attributes
Object
Domain controller is the physical object.
It is the Relative Identifiers (RID) & Security Identifiers (SID) that uniquely identifies an object throughout the Active Directory Domain. On page 85
The logical structure of active directory include forest, domains, tree, OUs and global catalogs.Domain : a group of computer and other resources that are part of a windows server2003 network and share a common directory database.Global catalog : Global catalog used to catch information about all object in a forest , the global catalog enables users and applications to find object in an active directory domain tree if the user or application knows one or more attributes of the target object.Tree : Tree as is collection of Active directory Domain, that means the trust relationship can be used by all other domain in the forest as a means to access the domain.Organization Unit - Organization Unit is a Active directory container into which object can be grouped for per mission management.Forest : Active directory forest as due to represents the external boundary of the directory service.These are two types of active directory forest :-I) Single Forest2) Multiple forest
schema attributes
acl
ou