Active Directory OU and GPO Map
An Active Directory OU and GPO map records the logical groups that organize devices or users and the policies linked to them. The domain is the starting point, with organizational units below it and policy objects connected to the OUs they affect. A small map can answer the practical audit question: which devices receive which policy? Use clear OU labels based on department, device class, or administration boundary. Show separate policy objects when their scope differs. This is especially useful before changing a baseline, moving computers between OUs, or reviewing the controls assigned to privileged workstations. Keep it focused on policy scope; domain controllers and network hardware belong in an infrastructure topology.
Open it in the AI editor with a prompt pre-filled — keep what works, change what doesn't.
Scenario
Review which group policies apply to departmental and administrative devices.
Key decisions
- Baseline policy: Shared controls are linked to the standard user OUs.
- Dedicated admin policy: Privileged devices receive a separate policy path.
- Department OUs: The groups make policy scope easy to review.
When to reuse this
Use this logical view for policy audits and change reviews, not for switch ports or physical cabling.
Frequently asked questions
What is an organizational unit?
What is a GPO link?
Why map GPO scope?
More active directory examples
Try the diagram makers.
Tweak it with chat, export PNG/SVG, or fork it for your own use case.