Hi,
Maybe you can try this :
$ou = "AD:\OU=test,DC=test,DC=com"
$group = Get-ADGroup administrators
$sid = new-object System.Security.Principal.SecurityIdentifier $group.SID
$acl = get-acl $ou
$ace = new-object System.DirectoryServices.ActiveDirectoryAccessRule $sid,"GenericAll","Allow"
$acl.AddAccessRule($ace)
set-acl -AclObject $acl $ou
Best wishes,
Young Yang