How do I let admins only delete the OUs they created?

Hi
I'm trying to get a controlled AD designed & implemented, but I'm running into a few problems with delete rights in a Windows 2003 AD.

My situation is this: Each physical branch office is going to relate to an OU in the AD. There will be a parent OU, lets call it MASTER, with an OU for each branch office, so let's say OU1, OU2, OU3, and OU4. That's the default set of OUs each branch will receive. I want to delegate so that the each branch admin can, if they so desire, either create more new OUs directly in the branch OU, or create more new OUs in one of either OU1, OU2, OU3, or OU4. I want them to be able to delete whatever they have created themselves, but I **DONT** want them to create any of the defaut set (OU1/2/3/4). I've tried assigning various permutations, such as allowing full control on the branch OU, but explicit deny permissions on the standard OU set, but nothing seems to work because of the way Windows 2003 processes the inherited vs explicit permissions set.

Its proving very annoying!

Thanks for your help
tbennett35Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

LauraEHunterMVPCommented:
Go to the Properties tab of OU1, OU2, OU3, OU4. Click Advanced from the Security tab and look for the option to configure security settings that apply to "Child objects only" - this will confer rights to create objects underneath Ou1/2/3/4 without the user having rights to modify or delete the OU itself.  You'll have to do this 4 times, once for each of ou1/2/3/4.

Hope this helps.

Laura E. Hunter - Microsoft MVP: Windows Server - Networking
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
tbennett35Author Commented:
Laura Hunter...well well well...I bought your book!

Got to hand it to you...that must probably be about the only thing I didn't try, because I was ripping my hair out yesterday! It worked a treat!
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
OS Security

From novice to tech pro — start learning today.