Hi,
Check if the inheritance option is enabled on the ACLs of admin accounts.
Please don't forget to mark this reply as answer if it help you to fix your issue
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hi,
I created a unit organisation and set delegation to give to some users the permission to edit all users in this OU.
We have a problem with some admin accounts. the delegation doesn't work.
Hi,
Check if the inheritance option is enabled on the ACLs of admin accounts.
Please don't forget to mark this reply as answer if it help you to fix your issue
Hi,
It may caused by the Security Descriptor Propagator (SDPROP) if the user was in the protected group.
This background process runs, by default, every sixty (60) minutes on the Domain Controller holding PDC Emulator FSMO role in an Active Directory domain.
Even if you delegate (change) permissions on Domain Admins group, Active Directory will overwrite them by setting the ones used on AdminSDHolder container.
Following link for your reference:
https://social.technet.microsoft.com/wiki/contents/articles/22331.adminsdholder-protected-groups-and-security-descriptor-propagator.aspx
Best Regards,
Maybe you can verify the permissions.
https://social.technet.microsoft.com/wiki/contents/articles/6477.active-directory-how-to-view-or-delete-delegated-permissions.aspx
--please don't forget to Accept as answer if the reply is helpful--