I prefer using the OU structure rather than group membership. You have to put a computer in an OU but group membership is not compulsory. Depending on what you are trying to acheive though, OU structuring might not always make sense.

I generally use an OU structure cuz that is what GPOs are modelled after. Groups and ACLs can then be used for more granularity. The UDF I use is Howard's InContainer().
_________________________
Give a man a fish and he will be back for more. Slap him with a fish and he will go away forever.