Your network consists of a single Active Directory forest. The forest functional level is Windows Server 2008 R2. The forest contains two domains named contoso.com and na.contoso.com.
Contoso.com contains a user named User1. Na.contoso.com contains an organizational unit (OU) named Security.
You need to give User1 administrative rights so that he can manage Group Policies for the Security OU.
You want to achieve this goal while meeting the following requirements:
èUser1 must be able to create and configure Group Policies in na.contoso.com.
èUser1 must be able to link Group Policies to the Security OU.
èUser1 must be granted the least administrative rights necessary to achieve the goal.
What should you do?()