There are environments in which they have locked down permissions on SYSVOL policies and removed Domain Admin rights. Therefore when creating a GPO using Microsoft Advanced Group Policy Management (AGPM), Domain Admins would see a read permission on the GPO and nothing else. But, when creating a new group policy using GPOADmin you may see under delegation the following users and groups:

Still GPOADmin will add these groups and permissions even though they were locked down in SYSVOL.