Allow user in top level domain manage distribution lists on sub domain

We currently run windows 2003 server/exchange with a top level domain and sub domain.  Top level domain contains executives and sub domain contains operational users.  so the domain name space is similar to the following:  


One of the executives would like the ability to modify the members of the distribution groups located on the sub domain's exchange server.  Steps I've already tried to accomplish this by is by delegating control to that particular executive on the OU that all of the distribution groups are contained in.  This method, was found on multiple websites during my searching.  

Now I really do not want to give him admin rights for it's not the proper way to do this but might have to until I find a solution.  Could anyone help?


Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

You can set the delegation on distribution group level !?! ... rather than on that OU
sgaglioneAuthor Commented:
the distribution groups have inherited the right's from the OU level.  still no go.  have forced replication and has been 6 days since rights were set so i don't believe it's a replication issue either.  
sgaglioneAuthor Commented:
other reason why i did it on the OU level is so in the future any more distribution groups made, he can automatically modify them without my intervention and adding rights.
Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

> the distribution groups have inherited the right's from the OU level.
Nevertheless you can add additional rights on lower levels, so you can mix inherited and local rights

Whats about to put these list into a seperate OU?
sgaglioneAuthor Commented:
do you mean create a new OU and move the groups into that and also do a delegation of rights to change groups to that user?  
Yes, for example, in that way...

But note, a delegation is nothing else than giving a user admin permissions. The sense of this function is, to delegate administrative work of subtrees to aub-admins by simply a few mouse clicks.

If you do not want to give him admin access, you can add the user to the security list and give him only the right, you want assign to him. In that way, you have under control, what he can do or not. Putting these groups together is more a way to simplify administration

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Fonts Typography

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.