This guide explains the Active Directory advanced OU Segregation using the Object List Mode (More details can be found here). The idea of this is to prevent customers from being able to discover each other when using services such as RDS.
In existing environments we have made a powershell script which will secure the currnt Hosted Orgs for your customers. The script can be found at http://installer.solidcp.com/Files/Stable/Tools/SolidCP-dSHeuristics.zip
Before running this script you are required to edit the CustomerOU to point to the location SolidCP is setup to use.
Once this has been set you can run the script (Please ensure your logged in with a AD Domain Admin account) and it will secure the Hosted Orgs for you.
To make the change on existing OUs you need to remove the List Content & List Object as detailed here: https://social.technet.microsoft.com/wiki/contents/articles/29558.active-directory-controlling-object-visibility-list-object-mode.aspx#Removing_List_Content_amp_List_Object