Organization units (OUs) are a flexible organizational structure that enable configuring Jamf Safe Internet policies at different levels of your organization hierarchy. This allows you to manage devices. With OUs, you can do the following:
Configure policies
Manage devices from a single point
View reports from a single point
A super admin can define whether admins have access to one, multiple, or all leaf OUs. Only admins with access to all OUs can set policies that apply across your whole organization hierarchy.
Use Cases
You may want to use an OU to do the following:
- Create a sub level OU per location or department —
This allows for flexible management and policies. Each leaf OU can have its own administrators assigned to it.
Organization Hierarchy
One OU at root level is equivalent to one portal in Safe Internet, which represents one enterprise (for example, Jamf). If you have more than one OU, you can create a root level policy that is inherited across all leaf OUs (for example, Jamf UK, Jamf AUS), and all groups within those OUs. Further changes at lower levels can be made to override your root level policies.
The following table describes the hierarchy levels:
| OU Level | Description |
|---|---|
Root OU |
|
Leaf OU |
|
Group | A group level sits under the leaf OU. You can create multiple groups and set web protection policies per group. |
Parent OU | A parent OU is an OU one level higher than another level in the structure. |
Child OU | A child OU is an OU one level lower than another level in the structure. |
Inheritance and Overrides
Rule configurations are inherited from the root OU level by default. You can make changes at the leaf OU level that override the root OU level rule configurations.
Override a root OU level rule configuration by clicking Override at the leaf OU level.
To revert an overridden rule configuration back to the root level policy, change the setting back to Inherit.
If you click Override but don't make any changes, you must click Inherit to continue to inherit the policy from the root OU level.
You can create a root level policy rule to notify users when a phishing attack occurs on their device, which applies to your whole organization. If you want to override this for one specific leaf OU, for example, a school year group, create a policy override for the year group leaf OU to not notify those users.
Checking for Changes at the Leaf OU or Root OU Level
Select an OU under in Safe Internet to view changes made at either a leaf OU level that you're currently logged into or at the root OU level.