In large Active Directory environments, the administrative burden may be high. Therefore, in environments with several teams of administrators and service desk personnel, delegation is needed. This way, for instance, service desk personnel may reset passwords, application administrators may change group memberships, and only true Active Directory admins may manage OUs.
Delegating control of an OU
Getting ready
To perform delegation of control, you'll need to be signed in with an account that is a member of the Domain Admins group or have full control privileges of the OUs you want to delegate control over.