It is possible but my experience is it doesn't work correctly,
even if you move the DCs so child-OUs within the DC-OU
(so that DC Default Policy still applies).
I have heard some sort of rumor about a KB article but have
never seen it -- my experience is they just don't like it.
It should work, and the only problem would be the change in Security Policy
and GPO's that are linked to Domain Controller OU. If you link Domain
Controller GPO to that (new) OU and move DC it should work. You could also
create a new GPO for that OU which would mirror Default Domain Controller
GPO.
My response to this is it is generally discouraged and if you do proceed, proceed at your own risk. There are poorly
written applications out there that could fail (both third party and MS) so just test everything you want to use prior
to doing this in production.
Want to reply to this thread or ask your own question?
You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.