How to delegate control at Active Directory Site Level
We are most familiar with delegating administers control at OU level or Domain level in Active Directory. You can also use this method to deny an administrator at Active Directory Site Level. Follow below steps to delegate control at Active Directory Site Level.
- Open Active Directory Sites and Services console on a domain controller
- Right click the Sites container and choose Delegate Control.
- Click Next, use Add button to select the user or group, click Next
- On the Active Directory Object Type screen, choose defaults
- Click Next, On the Permissions screen, check the desired permissions type check boxes.
- Click Next and Finish
