I have delegated control on all containers and OU's containing user accounts to a group called IT-Helpdesk. At this point they should have full control but although they can check the "User must ...
http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_2003_Active_...