Delegate AD-Group-Management for specific groups

Hello,

Noob here :-(

I want to delegate the AD-Group-Management for specific groups to specific standard ad users, I hope this is manageable via web-console of arm. I tried settings with data owner and specific resources (only access to a OU of our ad), but i don't get a working solution.

Can you help me if my szenario is possible and how i can set the necessary settings?

Thanks 

Christian