I don't know of an easy/magic way. That kind of stuff should be kept
documented, otherwise you are going to have to look through all the security
property pages for AD containers such as domain/OU looking for non default
user or group that would indicate some sort of delegation. --- Steve