I really appreiciate you taking time to share your experience and advice! I've already skimmed your first link, and I'm checking out the one from Meraki now.
According to the Meraki docs, there's a way to scope AD to only allow authentication from a particular OU, but that's not a very practical method when you'd have to set a "deny" for the admin account on all the OUs except the one you're using. We have way too many OUs for that to work...
thanks again for your time and effort!