Your network contains an Active Directory domain named contoso.com. The domain contains 100
user accounts that reside in an organizational unit (OU) named 0U1. You need to ensure that a user
named User1 can link and unlink Group Policy objects (GPOs) to OU1. The solution must minimize
the number of permissions assigned to User1.
What should you do?
A.
Modify the permissions on OU1.
B.
Run the Set-GPPermission cmdlet.
C.
Add User1 to the Group Policy Creator Owners group.
D.
Modify the permissions on the User1 account.
And by “Modify the permissions on OU1.” you mean “Delegate control”. THANKS!
indeed