Did an inventory of departments in our Active Directory domain and found too damned many to have them be at all meaningful.
If you want to segment e.g. retail store employees, it helps if they aren't in a department consisting of one store in Auckland, or Runcorn or wherever.
Password hash sync is definitely worth it. I also agree on the subject of UPN matching email address. I've got some legacy apps that cause all kinds of problems if we change a UPN, and I have a mixture of users where their UPN is definitely not their email address - and that's just something I have to explain over and over again.