Adaxes Web Interface HelpShow AllHide All

Business Unit Overview

Business Units are virtual collections of Active Directory objects, that allow to organize objects in an alternative way without breaking the Active Directory structure. They can be used to manage and view objects collectively. For example, you can use Business Units to group users from Human Resources departments located in different domains. After that, you will be able to view them collectively and to assign Security Roles, Business Rules and Property Patterns on them.

To facilitate Business Units browsing, they can be organized in containers. This provides additional capability to create complex alternative hierarchies of AD objects.

Objects are added to Business Units with the help of the following membership rules:

You can add several membership rules for a Business Unit. If the same objects are included by one membership rule and excluded by another, membership is determined by the priority of these rules. The priority is defined in the following order:

  1. Specific Objects - this rule has the highest priority. If an object is included by this rule type, it cannot be excluded by the other rule types.
  2. Group Members - this rule has the second priority. If an object is included by this rule type, it can be excluded by the Specific Objects rule only.
  3. Container Children - this rule has the third priority. If an object is included by this rule type, it can be excluded by the Specific Objects and Group Members rules only.
  4. Query Results - this rule has the lowest priority. If an object is included by this rule type, it can be excluded by any other rule type.
    The rules of the same type have different priority if one of them includes objects and the other excludes them. The excluding rule has a higher priority.

For example, the Administrators Business Unit has two membership rules, one of which includes members of the Domain Administrators group, and the other excludes as a specific object the Security Admin user that is a member of this group. In this case, the Business Unit will contain all members of the Domain Administrators group except for Security Admin, because Specific Objects rule has a higher priority than Group Members rule.