i have one domain and serveral domain controller in different cities , and different cities has their dc, Any idea to make a tailor made administrator theat delgate the full right to specidfic cities only ?
e.g. city1_admin ,city2_admin, they should have full right in their own cities .
i delgate the ou to them and give themsever operator right but seem they can cretea /delete but still cannot change sharing and permission in their own servers ...but if gave them domain admin it is too big.
any idea to tune just give them create /delete/ change permisision right for their OU and DC only , but they have the right to share to other city people.