You need to design an access control and permission strategy for user objects in Active Directory.What should you do?()
- AMake the members of the AdvancedSupport security group members of the Domain Admins security group
- BGive each desktop support technician permission to reset passwords for the top-level OU that contains user accounts at their own location
- CDelegate full control over all OUs that contain user accounts to all AllSupport security group
- DChange the permissions on the domain object and its child objects so that the BasicSupport security group is denied permissions. Then, add a permission to each OU that contains user accounts that allows AllSupport security group members to reset passwords in that OU