Delegate AD DS Site Topology Administration

Applies To: Windows Server 2008, Windows Server 2008 R2

Configuring the site topology for the forest begins when the forest owner delegates administration of the Active Directory Domain Services (AD DS) sites and site topology to the site topology owner.

To delegate AD DS site topology administration in your environment

  1. Create a global group named SiteAdmins in the forest root domain.

    For more information about creating a group, see Create a new group (

  2. Add administrative users to the SiteAdmins global group.

    For more information about adding members to a group, see Add a member to a group (


The user accounts that you add must reside in the forest root domain. If you want to add users from regional domains to this group, the group must be a universal group and the forest root domain and the regional domain must operate at the Windows Server 2003 or Windows Server 2008 functional level. For more information about group scope in Active Directory Domain Services, see Group scope (

  1. Open the Active Directory Sites and Services snap-in, click Start, click Administrative Tools, and then click Active Directory Sites and Services.

  2. Right-click the Sites node, and then click Delegate Control.

  3. Complete the Delegation of Control Wizard to delegate full control of the Sites node to the SiteAdmins group.