Hi,
You can use the powershell commend to set the ACLs settings on this OU :
$oupath = "OU=Groups,DC=domain,DC=local"
$User = get-aduser -identy Username
$objACL = Get-ACL "AD:\\$oupath"
$objACE = New-Object System.DirectoryServices.ActiveDirectoryAccessRule($User,"DeleteChild","Deny", 'None'')
$objACL.AddAccessRule($objACE)
Set-acl -AclObject $objACL "AD:${OU}"
You can refer to the following link to get more details about how set active directory delegation using Powershell:
active-directory-delegation-via-powershell
Please don't forget to mark helpful reply as answer