Scenario: You want to give Full Control delegate access to a AD Group to a specific AD Organizational Unit and its sub objects.
Scriptlet:
#Add Rights Indiviudally
$ou = "AD:\OU=New,DC=Domain,DC=Com"
$group = Get-ADGroup "Exchange Admins"
$sid = new-object System.Security.Principal.SecurityIdentifier $group.SID
$acl = get-acl $ou
$identity = [System.Security.Principal.IdentityReference] $SID
$adRights = [System.DirectoryServices.ActiveDirectoryRights] "GenericAll"
$type = [System.Security.AccessControl.AccessControlType] "Allow"
$inheritanceType = [System.DirectoryServices.ActiveDirectorySecurityInheritance] "All"
$ACE = New-Object System.DirectoryServices.ActiveDirectoryAccessRule $identity,$adRights,$type,$inheritanceType
$ace = new-object System.DirectoryServices.ActiveDirectoryAccessRule $sid,"GenericAll","Allow","All"
$acl.AddAccessRule($ace)
set-acl -AclObject $acl $ou