Delegation doesn't work on some Admin accounts

MamadouCoulibali-4946 486 Reputation points


I created a unit organisation and set delegation to give to some users the permission to edit all users in this OU.

We have a problem with some admin accounts. the delegation doesn't work.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,999 questions
0 comments No comments
{count} votes

Accepted answer
  1. Thameur-BOURBITA 32,606 Reputation points


    Check if the inheritance option is enabled on the ACLs of admin accounts.

    Please don't forget to mark this reply as answer if it help you to fix your issue

2 additional answers

Sort by: Most helpful
  1. Fan Fan 15,306 Reputation points Microsoft Vendor


    It may caused by the Security Descriptor Propagator (SDPROP) if the user was in the protected group.
    This background process runs, by default, every sixty (60) minutes on the Domain Controller holding PDC Emulator FSMO role in an Active Directory domain.
    Even if you delegate (change) permissions on Domain Admins group, Active Directory will overwrite them by setting the ones used on AdminSDHolder container.
    Following link for your reference:

    Best Regards,

    1 person found this answer helpful.

  2. Dave Patrick 426.2K Reputation points MVP

    Maybe you can verify the permissions.

    --please don't forget to Accept as answer if the reply is helpful--