Identity with Windows Server 2016 — Question 113

Your network contains an Active Directory domain named contoso.com.
You have an organizational unit (OU) named OU1. A Group Policy object (GPO) named GPO1 is linked to OU1.
You create a user named User1, and you assign User1 the Full control permission to OU1.
Which administrative action for GPOs can User1 perform?

Answer options

Correct answer: A

Explanation

User1, having Full control permission on OU1, can link an existing GPO from the domain to OU1, which is why option A is correct. However, User1 does not have permission to create a new GPO (option B), add templates (option C), or edit User Rights Assignments (option D), as those actions typically require higher-level permissions than Full control of an OU.