- Log on to the computer as a member of the Domain Admins group.
- Open Active Directory Users and Computers.
- Click View, and then click Advanced Features.
- First, apply permissions on the OU that you want to protect. To do this, right-click the OU that you want to protect, and then click Properties.
- In OU Properties, click the Security tab, and then click Advanced.
- On Advanced Security Settings, click Add, type Everyone, and then click OK.
- In Permission Entry, in Permissions, select the Deny check boxes for Delete and Delete subtree.
- Select the check box for Apply these permissions to objects and/or containers within this container only.
- Click OK to close Permission Entry.
- On Advanced Security Settings, click Apply.
- Review the Windows Security warning, and then click Yes to continue.
- Click OK to close the Advanced Security Settings, and then click OK to close OU Properties.
- Second, apply permissions to the parent container of the OU that you want to protect. To do this, right-click the parent container, and then click Properties.
- In ContainerProperties, click the Security tab.
- Click Add, type Everyone, and then click OK.
- In Permissions for Everyone, select the Deny check box for Delete All Child Objects, and then click Apply.
- Review the Windows Security warning, and then click Yes to continue.
- Click OK to close Container Properties.
http://technet.microsoft.com/en-us/library/cc739350%28v=ws.10%29.aspx