LOGBOOK

HELP

Quiz Entry - updated: 2026.09.29

Why would a user OU be split into Privileged, Restricted and Service Accounts?

So that accounts with different risk get different policies and different handling: elevated accounts, ordinary users and non-human service accounts.

  • Privileged: accounts with elevated rights, for example department heads or administrators. They deserve stricter policies (stronger authentication, tighter logon restrictions, more auditing) because their compromise hurts most.
  • Restricted: ordinary employees with limited rights.
  • Service Accounts: accounts that a service or application runs as, not a person. They often have long-lived passwords and broad rights, should not log on interactively, and need their own policies.

Separating them into OUs is what makes it possible to link a different GPO or delegate differently for each group of accounts.

Gotcha: the OU itself grants no rights. Putting a user into Privileged does not make them privileged; only group memberships and permissions do.

Go deeper:

From Quiz: ISLAB / Access Management with Active Directory | Updated: Sep 29, 2026