Administrators can delegate control based on OUs. This will provide control to individuals or groups to manage objects within OUs.
In my demo, I am going to provide delegated control for Asia IT Team members to manage objects under the Asia OU:
- To do that, log in to the domain controller as the Domain Admin and open ADUC. Then, right-click on the relevant OU and click on Delegate Control...:
- Then, it will open up the wizard; there, select the individuals or group that you'd like to provide delegated control to. In this demo, this is Asia IT Team (REBELADMIN\Asia IT Team):
- In the next window, system will provide the ...