What are the default Users and Computers containers at the root of an AD domain for, and why should objects not stay there?
They are the default landing places: new user accounts created without a target location, and computers that join the domain, end up there.
When a machine is joined to the domain, its computer account is created in Computers unless someone pre-staged it elsewhere. Users holds the default accounts and groups created with the domain (Administrator, Guest, Domain Users, Domain Admins and more).
Because they are containers and not OUs, no GPO can be linked to them directly; only domain-wide policies reach their objects. A new laptop that stays in Computers therefore gets none of the OU-level security settings. Good practice is to move objects into the proper OU (or redirect the default location with redircmp/redirusr).
Go deeper:
Microsoft Learn: Redirect the users and computers containers โ why objects in the default containers miss OU policies, and how
redirusr/redircmpfix it.