What is the difference between an organizational unit (OU) and a container in Active Directory?
Both hold objects, but only an OU can have Group Policies linked to it and administrative rights delegated on it; a container is just a folder.
An OU is the building block for administration. You can link a GPO to it (all computers and users inside get those settings), delegate control over it (the helpdesk may reset passwords in this OU only), and nest OUs inside each other.
A container (the built-in Users, Computers and Builtin folders, shown with a plain folder icon) can hold objects but cannot have GPOs linked to it and cannot be nested into your own structure. You also cannot create new containers in the normal admin tools.
Why it matters: an object left in a container misses every OU-linked policy. That is why real objects should be moved into the designed OU structure.
Go deeper:
Wikipedia: Organizational unit (computing) โ OUs as the smallest unit for Group Policy and delegation.