Our organization is creating a preliminary design for Active Directory, and a question has come up. One of our remote administrators refuses to use and OU, and is requesting a Child domain. However, his users will have to remain in the Parent Domain. My question is, can an administrator of a child domain be granted administrative permissions to only a subset of users in the parent domain, without creating an OU in the parent domain?