Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To delegate permissions in on-premises Active Directory Domain Services (AD DS), scope the work to an organizational unit (OU), assign the required rights to a role-based security group, and verify inheritance and object-creation permissions. The Delegation of Control Wizard in Active Directory Users and Computers handles common tasks and lets administrators define custom ones. This approach gives staff defined directory responsibilities without making them Domain Admins.

What Active Directory delegation does

Delegation of control assigns specific administrative tasks to users or groups within a chosen scope. In AD DS, that scope can be a domain or an OU, and rights assigned at a parent container can affect objects beneath it. Microsoft documents common tasks such as managing user accounts, resetting passwords, changing group membership, joining computers to a domain, and managing Group Policy links. Administrators can also define custom tasks by selecting object types and permissions. See Microsoft’s Delegation of Control Wizard guidance.

This article covers on-premises AD DS, not delegation of roles in Microsoft Entra ID. Microsoft’s relevant guidance applies to Windows Server 2016, 2019, 2022, and 2025; check the current documentation for interface or version changes.

Design the scope before granting rights

Define the task

Write down the exact actions the role needs, such as resetting passwords for users in a particular department. Choose the narrowest task that supports the work; a broad account-management permission is not a substitute for a carefully chosen password-reset permission.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose an OU boundary

Place the objects that need delegated administration in a deliberate OU, then delegate at that OU rather than defaulting to the domain. Microsoft recommends keeping default containers and OUs under service-administrator control and creating additional OUs when data administrators need to manage objects without changing those controls. Delegation groups in the same domain as the administrators and target OUs must be global groups under Microsoft’s account-OU guidance. See Microsoft’s account-OU delegation guidance.

Use groups to represent roles

Grant rights to a security group for a defined administrative responsibility, then manage membership in that group. This makes it easier to review who can perform the work than granting permissions separately to named users. Avoid using highly privileged groups as a shortcut for routine administration.

Rank #2
Sale
Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022
  • Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022, 3rd Edition
  • ABIS BOOK
  • Packt Publishing

Check inheritance and object creation

Permissions can be inheritable by child OUs, so determine whether the intended scope includes descendants before applying the delegation. Also examine create-object permissions carefully: Microsoft notes that the ability to create an object can permit manipulation of its attributes, while the ability to create a container may allow control over objects placed inside it. A permission label alone may not reveal the practical reach of the grant. See Microsoft’s account-OU delegation guidance.

Delegate control with the wizard

  1. Prepare the change: record the target domain or OU, the role group, the task, and whether child OUs should be in scope.
  2. Open the target: in Active Directory Users and Computers, select the domain or OU that will define the scope, then choose Delegate Control.
  3. Select the group: add the role-based group that should receive the rights.
  4. Choose the task: select a listed common task, or choose the custom-task option and specify the object types and permissions required.
  5. Complete and record: finish the wizard and document the resulting delegation and the group membership responsible for it.

The person configuring delegation needs Domain Admin membership or other delegated authority sufficient to make that change, and the management computer needs Remote Server Administration Tools (RSAT). The wizard’s options and scope are described in Microsoft’s wizard documentation.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Validate the result before broad rollout

Use a test OU and representative test accounts to confirm what the group can and cannot do. Check the requested task, inherited access on child OUs, and any ability to create objects or containers. This is a prudent validation step because scope, inheritance, and object-creation rights affect effective authority; it is not a Microsoft-mandated test procedure.

  • Confirm a test member can perform the intended task on the intended objects.
  • Confirm the member cannot perform unrelated tasks or act outside the intended OU subtree.
  • Check whether delegated rights are inherited by children and whether that is deliberate.
  • Review object-creation rights for unintended control over newly created objects or containers.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Audit and maintain delegated access

Microsoft recommends enabling auditing for account OUs to track changes to administrative users and groups, and recommends alerts for changes to privileged-group membership and properties. Assign an owner to review those events, and periodically reassess whether each role still needs its permissions. The cited guidance does not specify a universal review interval. See Microsoft’s account-OU guidance and Microsoft’s least-privilege administrative-model guidance.

For routine work, do not use Enterprise Admins, Domain Admins, or Administrators as a substitute for scoped delegation. Microsoft identifies these as highly privileged groups and recommends least privilege. See Microsoft’s least-privilege guidance.

Compare delegation designs

Design choice What to evaluate
Scope Domain-wide authority versus one OU or a limited subtree.
Task breadth Control over all objects versus selected object classes, attributes, or tasks.
Inheritance Whether child OUs and their objects receive the rights.
Role membership Whether maintainable security groups represent responsibilities.
Object creation Whether creating objects or containers could also confer wider control.
Auditability Whether changes to role membership and managed OUs are recorded and reviewed.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.