I'm not saying you can't, but if any Director of Security at any large business found you trying to do this I'm sure they would throw the book at you.

Why on Earth do you want "normal users" creating other user accounts and all the other permissions that often go with it such as creating folders and shares and setting permissions on those.

You as an Administrator can create thousands of accounts within minutes with scripting so I don't see the need to have a normal user create accounts.

What if someone, somehow gained access (even as a basic user with no rights) got onto one of your systems. If they saw, found this Domain Admin account with the password they could wipe out your entire network within seconds and you couldn't stop them until it was too late.

In reality it would "probably" never happen, but "if" it did then I wouldn't want to be in your shoes.

I assume they hired you to do Admin work and creating user accounts is part of being a Network Admin.

Please explain in more detail why you want or think you need to have normal users creating user accounts. Please convince me and others why this has to be done this way,
 
 
 

As I said though, if you're hell bent on doing this then the RUNNAS program created by Shawn Tassie is about the most secure thing I've seen (barring AD delegation) around anywhere.

RUNNAS - Tokenized Runas Utility
http://www.kixtart.org/ubbthreads/showflat.php?Cat=0&Number=153599