Most organizations are still managing Active Directory (AD) in environments designed decades ago – often by people who are no longer with the company. What started as a logical organizational unit (OU) structure has slowly become brittle and feels too risky to change. Even when everyone agrees it’s not ideal, rebuilding your OU’s from the ground up just doesn’t feel realistic. It’s disruptive, time-consuming and carries a high risk of breaking something critical.
But modernizing your AD doesn’t require tearing it down and starting over.
In a recent session led by One Identity experts Phil Hayes and Eric Hibar, they explored why traditional OU structures have become a liability – and how organizations can regain control and flexibility using Active Roles managed units, without rebuilding an OU structure from 2003.
Why traditional OU structures no longer work
Active Directory was never designed to scale cleanly over decades of organizational growth. As companies evolve, AD environments tend to inherit design decisions that no longer make sense: OUs organized by geography, department, job code or even graduation year. Over time, layers of group policies, scripts, applications and delegated permissions get hard-coded to that structure.
Eventually, no one fully understands why things are organized the way they are – only that changing anything feels dangerous.
This creates several systemic problems:
-
Limited visibility: Native AD makes it difficult to see who owns what or who has access to which objects
-
Inconsistent delegation: Permissions are tied directly to OUs, leading to one-off exceptions instead of enforceable policies
-
Privilege creep: Elevated access accumulates over time and rarely gets revoked
-
Risky change management: Moving or restructuring OUs can impact GPOs, applications and scripts with a massive blast radius
-
Reactive cleanup: Problems are addressed during audits rather than prevented at creation
In short, static OUs lock organizations into outdated administrative models that don’t reflect how IT teams actually operate today.
Why rebuilding AD isn’t the answer
When faced with these challenges, many teams consider a full OU redesign. In reality, that option is often ruled out quickly – and for good reason.
GPO dependencies, application hard-coding and legacy scripts make structural changes extremely risky. Even well-planned changes require extensive testing and still introduce the possibility of downtime. For large enterprises with hundreds of thousands of users and complex delegation models, the risk often outweighs the reward.
Hayes shares from firsthand experience: His organization explored a full redesign but ultimately rejected it due to the sheer number of dependencies tied to their OU structure. They needed a way to modernize control without destabilizing the environment.
Introducing managed units: A logical layer of control
This is where Active Roles managed units come in.
Managed units create a logical, rule-based administrative layer that sits above native AD – often described as a “virtual OU.” Instead of organizing objects by where they live in the directory, managed units organize users, computers, groups, and any other AD object based on attributes and rules.
For example:
-
All full-time employees
-
All members of the Finance department
-
All computer objects, regardless of OU
-
All users with admin-level history (using attributes like adminCount)
These containers exist outside the native OU structure, allowing organizations to decouple delegation and policy from physical AD layout.
5 core limitations solved by managed units
Managed units address the five core limitations of traditional OUs while leaving the underlying directory intact.
-
Improved visibility
Admins and help desk teams can work from logical views that reflect how the business actually operates – across OUs, domains and even hybrid environments.
-
Consistent, repeatable delegation
Instead of manually assigning permissions at every OU level, teams can define role-based delegation once and apply it consistently across managed units. No drift. No one-off exceptions.
-
Policy-driven object creation
Active Roles enables governance at creation time – not after the fact. Attributes can be standardized, required fields enforced and dropdown values used instead of free-text entries.
-
Reduced risk and blast radius
Because managed units don’t require changes to native OU structures, organizations can modernize safely – without breaking GPOs, applications or scripts.
-
Scalable growth without privilege sprawl
As environments expand, managed units provide a clean way to scale delegation and administration without accumulating unmanaged access over time.
A real-world example
In Phil’s previous organization – a massive, divisionalized enterprise – managed units enabled a field-based, role-driven delegation model that simply wasn’t possible with native AD alone. Each division mapped its objects to managed units, while permissions were defined once per role and reused consistently.
The result? No redesign. No disruption. Just modernized governance layered on top of an existing directory.
For the first time, object creation and lifecycle management were controlled by policy instead of cleanup scripts and audits.
Flexibility without a full restructure
Some organizations prefer flat directory models. Others don’t. Managed units support both.
Whether you want a simplified view of all users or detailed segmentation by role, department, or risk level, managed units let you choose – without forcing structural change in AD itself.
That flexibility is what makes them so powerful: They modernize how AD is managed without asking organizations to rebuild what already exists.
In conclusion
Traditional OU structures weren’t built for modern scale, complexity or security demands. But modernizing AD doesn’t mean you have to start over. By introducing a logical layer of control with Active Roles managed units, organizations are simplifying delegation, improving visibility, enforcing standards, and reducing risk – without disrupting the directory they depend on.
Modern governance doesn’t require a rebuild – just a smarter way to manage what’s already there.