Memory hook: An OU sets policy; a group gathers people.
Must remember
- An organizational unit provides a hierarchy for inherited settings; groups collect members for communication, access and supported policy targeting. A user has one OU placement but can belong to many groups.
- Provision manually, in bulk or through supported directory synchronization. GCDS/Directory Sync synchronize selected directory data; SAML SSO delegates authentication and is not itself complete account provisioning.
- An alias gives an existing user another address; a secondary domain can contain separate users. Verify domain ownership before enabling it and plan primary-domain changes carefully.
- Suspension blocks access while retaining the account; deletion has recovery limits; an Archived User license can retain supported former-user data. Transfer Drive ownership and address legal holds before offboarding.
- Manage licenses, password resets, recovery settings, attributes and aliases as distinct tasks. Use staged changes and least-privileged delegated administrator roles.
- Distribution groups deliver mail; Collaborative Inbox adds assignment/work handling; dynamic groups derive membership from attributes. Resource calendars represent rooms or equipment with buildings, features, capacity and booking permissions.
Review details
Security groups identify groups intended for access-control use; they differ from a simple mail distribution decision. Configuration groups can override supported settings for a subset of people without moving everyone into another OU, but group precedence and supported settings must be checked. A domain alias supplies alternate addresses for existing identities; a secondary domain permits distinct identities.
For migration, distinguish account provisioning from historical data migration. Importing old mail does not configure MX, enable service access or grant a license. For offboarding, verify the required legal preservation and destination ownership before taking away the license or deleting the account.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| A team needs policy exceptions | Use a supported group override or a deliberate OU design. |
| An employee leaves during litigation | Preserve required data and holds before suspension, archival or deletion. |
Traps
- Deleting an account is not a harmless way to remove a license.
- An email alias is not a separately licensed mailbox or identity.
Active recall
1. How many groups may a user join?
Many; group membership differs from the single OU placement.
2. What does SAML SSO do?
It delegates authentication to an identity provider using assertions.
3. Why transfer file ownership before deletion?
To preserve business access and avoid losing user-owned content.
4. Which object represents a meeting room?
A bookable resource with a resource calendar and permissions.
5. When choose a dynamic group?
When membership should follow supported directory attributes automatically.