You need to design an access control and permission strategy for user objects in Active Directory.What should you do?()
A. Make the members of the AdvancedSupport security group members of the Domain Admins security group
B. Give each desktop support technician permission to reset passwords for the top-level OU that contains user accounts at their own location
C. Delegate full control over all OUs that contain user accounts to all AllSupport security group
D. Change the permissions on the domain object and its child objects so that the BasicSupport security group is denied permissions. Then, add a permission to each OU that contains user accounts that allows AllSupport security group members to reset passwords in that OU