How it works...

Microsoft deliberately chose to put devices in the Computers container and user objects in the Users container, because containers can't have policies attached, so even if an Active Directory administrator messed up the directory, at least you should be able to join a device and sign in to it without having group policy objects applied from the container.

Active Directory admins can change the default locations for objects. Since this action has the potential to mess things up, Microsoft has decided to make this change available only on the command line, through two specific executables: