Enterprise Administrators always have full "Administrator" level control of GPOADmin, identical to the service account.
They are intended to be the accounts that can do everything, and may be needed if there are issues with the service account.
Domain Administrators are still restricted in the way any other user can be restricted.
There is no way to disable this behavior.
© ALL RIGHTS RESERVED. Feedback Conditions d’utilisation Confidentialité Cookie Preference Center