Quiz Entry - updated: 2026.09.29
Why would a user OU be split into Privileged, Restricted and Service Accounts?
So that accounts with different risk get different policies and different handling: elevated accounts, ordinary users and non-human service accounts.
- Privileged: accounts with elevated rights, for example department heads or administrators. They deserve stricter policies (stronger authentication, tighter logon restrictions, more auditing) because their compromise hurts most.
- Restricted: ordinary employees with limited rights.
- Service Accounts: accounts that a service or application runs as, not a person. They often have long-lived passwords and broad rights, should not log on interactively, and need their own policies.
Separating them into OUs is what makes it possible to link a different GPO or delegate differently for each group of accounts.
Gotcha: the OU itself grants no rights. Putting a user into Privileged does not make them privileged; only group memberships and permissions do.
Go deeper:
Microsoft Learn: Implementing least-privilege administrative models — why privileged accounts need separate handling.
Wikipedia: Principle of least privilege — the principle behind separating account types.