See below KB for minimum permissions required:
In order to test lack of permissions to create objects in AD follow below steps:
1- From a server with ADUC installed (AD Users and Computers), open CMD
2- Run below line:
runas /user:ADDomain\AccountUsedToAccessAD /netonly cmd
3- From the new CMD window just opened, run DSA.MSC to open "AD Users and Computers".
4- Try to create a test object in the corresponding OU.