As Part of the Minimum permissions guide the service request requires full delegation and ownership for each GPO:
- Using GPMC, delegate Edit settings, Delete, and Modify security to the service account for each existing GPO that will be managed by GPOADmin using GPMC.
- For each GPO managed by GPOADmin, verify that the Service Account has direct ownership of the GPO on the Owner tab of the Advanced Security Settings dialog box.
NOTE: This step can be automated after GPOADmin has been installed and configured using the GPOADmin.AddServiceAccountToALLGPOs.ps1 PowerShell script located in the Scripts directory of the install directory.