Why can’t I use regular Microsoft tools to manage an OU?
The delegation of control account’s permissions is confined to Quest Active Roles Server. This account does not have any privileges on CornellAD. When you connect to CornellAD using Microsoft tools and the delegation of control account, you do not get any additional privileges. This security model enables CIT to enforce the naming conventions and policies that are necessary to manage access to services and information. For example, in this model no one can create an account that looks like a NetID, thereby compromising an existing NetID and the data it has access to.