The sequence in which Group Policy is processed: the local policy first, followed by site, domain and organisational unit policies. The nearest, last-processed setting takes effect unless Enforced or Block Inheritance alters that.
Also called local, site, domain, OU.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains LSDOU in context, with comparison tables and the common traps.
Terms in this definition
- SEQUENCE
A schema-bound object that generates values on request via NEXT VALUE FOR without belonging to a table. One can feed several tables, restart, cycle or set aside a block of values; any value drawn inside a transaction that rolls back is gone.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- FIRST
A DAX function available only inside visual calculations. It fetches the value at the start of one axis of the visual's matrix, which makes it handy for comparing each point with the first; its opposite is LAST.
- Domain
A way of grouping workspaces by area of the business, in support of a data mesh approach. Items take on their workspace's domain, letting you filter the OneLake catalog by it, and certain tenant settings can be passed to domain admins; domains have no effect on access permissions.
- OU
Organisational unit, a container within LDAP or Active Directory; CSRs include it as a field too.
- Block Inheritance
Enforced links aside, Group Policy objects attached at parent levels won't reach an OU or domain where this is switched on.
Related terms
- Additional local administrators
Microsoft Entra ID P1 device setting that grants selected users local administrator rights across all Microsoft Entra joined devices. Targeting only some devices is not possible.
- Administrative unit
Used to confine a role assignment to a subset of a Microsoft Entra directory, such as just one region's users for a local helpdesk. A unit holds users, groups or devices; units cannot be nested, and including a group does not make its individual members part of the scope.
- Anyone link
A SharePoint or OneDrive link that opens the item for anybody holding it, with no sign-in, which means its use isn't auditable. Files in a Teams shared channel site can't be shared this way.
- ARP
Finds which MAC address belongs to an IPv4 address on the local segment.
- AS Path (hub routing preference)
Routing preference for a Virtual WAN hub under which the shortest BGP AS path wins regardless of where the route came from. When local routes tie, ExpressRoute is chosen over site-to-site VPN.
- AS-path prepending
Making a BGP route less attractive by repeating ASNs to lengthen its AS path, steering traffic towards a different site or path.
- Authentication context
A Conditional Access tag placed on just one sensitive area or action within an app (a particular SharePoint site, say, or activating a PIM role), so tougher sign-in conditions apply there without covering everything else in the app.
- az aks get-credentials
Fetches AKS cluster credentials and merges them into kubeconfig, letting kubectl connect. With --admin, it instead retrieves the local administrator credential, intended for emergencies.