Skip to content

Delegated Administration

A governed grant that lets a separate principal perform specified administrative operations over a defined technical scope.

Core Idea

Delegated administration is a governed grant that lets a separate principal perform specified management operations over a defined technical scope. In Microsoft Active Directory Domain Services (AD DS), an authorized administrator can assign directory tasks to a user or group for a selected domain or organizational unit (OU). In AWS Account Management, a management account can register a member account so its users and roles can perform supported account-management operations for other member accounts.[ref-4cd43c3f1258][ref-e0fe105d456d]

The grant has five roles: authority holder, separate delegate, managed scope, administrative operations, and a governing permission or registration framework. An ordinary right to use a resource, or an instruction to do work without the technical right, does not meet this definition. Least-privilege quality, auditing, active monitoring, and one universal withdrawal procedure are not presumed from the cited grant documents.[ref-4cd43c3f1258][ref-e0fe105d456d]

Scope of Application

AD DS offers common tasks including account management, password resets, group-membership changes, and policy-link management. The wizard selects a domain or OU container, a delegate, and a task or custom permission, with the chosen scope applying to relevant descendant objects. A specific instance must name its actual task and container.[^ref-4cd43c3f1258]

AWS permits one registered delegated admin account per organization for Account Management, provided all organization features and trusted access for the service are enabled. Registration occurs from the management account. Users and roles in the registered member account may call supported account namespace operations using AccountId for other member accounts. This is not blanket authority over every AWS service.[^ref-e0fe105d456d]

Clarity

Describe a grant by saying who grants, who receives, what can be managed, and where. “Admin access” alone hides the scope and operation. Separate the existence of a grant from whether it is appropriate and from what a delegate actually does with it. The official procedures document possible grants; they do not measure speed, error reduction, or complete oversight in deployments.[ref-4cd43c3f1258][ref-e0fe105d456d]

Manages Complexity

Delegation distributes some management tasks across an estate without requiring every recipient to become a central administrator. A wider grant gives the delegate more independent reach, while a narrower one leaves more operations with the central holder. It can also expand the potential scope of errors. The trade-off depends on actual tasks and target objects; neither source quantifies the operational result.[ref-4cd43c3f1258][ref-e0fe105d456d]

Abstract Reasoning

To classify a case, identify the holder, delegate, resource or service scope, administrative operations, and grant mechanism. If there is no separate recipient, the case is central administration. If the recipient merely reads or uses a resource, it is access rather than delegated management. If the actor owns the estate independently, there is no grantor-to-delegate relation. A broad grant can still be a delegation even when it is poor least-privilege design.

Knowledge Transfer

The role pattern travels from an AD DS OU to an AWS organization: holder → delegate → managed scope → allowed management operations. The wizard, OU tree, account registration, and API names remain product-specific. The live Prime Delegation of Authority has a fuller accountability/reporting and recall signature not established for every technical grant by these sources. The reviewed graph therefore records an approved unparented root with no strict parent edge.[ref-4cd43c3f1258][ref-e0fe105d456d]

Example

AD DS OU. An authorized administrator selects an OU in the Delegation of Control Wizard, chooses a user or group, and assigns a task such as resetting passwords. Holder → authorized administrator; delegate → chosen user or group; scope → selected OU and applicable descendants; operations → chosen password-reset task; framework → AD DS permissions. This is a documented procedure, not an observed organization outcome.[^ref-4cd43c3f1258]

AWS Account Management. With all features and trusted access enabled, an Organizations management account registers a member account for Account Management. Holder → management account; delegate → registered member account and its roles; scope → supported service functions for other organization member accounts; operations → supported calls with AccountId; framework → service-specific registration. It does not confer every AWS administrative function.[^ref-e0fe105d456d]

Neighborhood in Abstraction Space

Delegated Administration sits in a sparse region of the domain-specific corpus (100th percentile for distinctiveness): few abstractions share its structure, so a faithful description tends to retrieve it precisely.

Family — Unclustered & Miscellaneous (2551 abstractions)

Nearest neighbors

Computed from structural-signature embeddings · 2026-10-08

Not to Be Confused With

Ordinary resource access: use without authority to manage. Task assignment: an instruction without the permission. Credential forwarding: use of another identity’s credentials rather than a scoped grant. Central administration: no separate delegate. Least Privilege: a design principle that an actual broad grant may fail. Delegation of Authority Prime: a fuller governance structure whose recall/reporting requirements are not evidenced for every case here.[ref-4cd43c3f1258][ref-e0fe105d456d]

References

[^ref-4cd43c3f1258]: Microsoft, “Delegation of Control in Active Directory Domain Services”, Microsoft Learn, updated July 1, 2026, “In this article,” “Prerequisites,” and “Delegate control.” First-party AD DS documentation for domain/OU scope, delegate selection and selectable management tasks; no universal post-grant procedure inferred.

[^ref-e0fe105d456d]: Amazon Web Services, “Enable a delegated admin account for AWS Account Management”, AWS Account Management Reference Guide, accessed October 4, 2026, registration procedure. First-party service documentation for one registered member account, management-account registration and supported cross-account operations; not a claim about all AWS services.