You would need to write a script that queries the ACLs on every object
that could support an OU being created as a child and then pull out the
ACEs that apply (create child - any, create child - ou's, full control,
and anyone who can write the permissions for the object, and the owner
of the object) then any groups you would need to resolve into individual
users.
If you just want to know for a single location in AD, look at the ACL
manually and work it out, broad spectrum would take the script or if you
can find a third party tool to do it.
--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net
---O'Reilly Active Directory Third Edition now available---
http://www.joeware.net/win/ad3e.htm