If you want to modify the default permissions for GPOs, open ADSIEdit from Server Manager and connect to Schema, navigate to CN=Group-Policy-Container, then open Properties and edit the defaultSecurityDescriptor attribute. The permissions are written using the Security Descriptor Definition Language (SDDL).
Please refer to this help file for more details about SDDL.
https://learn.microsoft.com/en-us/windows/win32/secauthz/security-descriptor-definition-language
Also refer to this link for the steps.
https://sdmsoftware.com/tips-tricks/modifying-default-gpo-permissions-creation-time/
Best Regards,
Ian Xue
If the Answer is helpful, please click "Accept Answer" and upvote it.