I have a very large AD structure for our domain and would like to delegate GPO creation to other members of my staff without making them domain administrators. Do they need special rights or privileges?


There are two ways to allocate non-administrative accounts the ability to create GPOs. They are:

  • Make them a member of the Group Policy Creator Owners Group in AD Users and Computers
  • Grant them the right within the Group Policy Objects node on the Delegation tab. Anyone in this list can do so.