Select your OU, then Delegate Control.

Useful when you want a domain admin account that can only join computers to the domain.