Hello,
Here’s a brief overview of our AD. We have different OU’s for different sites and the local admins have been delegated the rights to Add/remove members from the domain local groups within their respective OU’s using the “Delegation of control Wizard”.
Lately we have been having issues and would like to remove the rights/ability of the local admins to REMOVE any group members, while still retaining the ability to add members as and when needed. How do we accomplish this?
Any suggestions?
TIA