What is a one sentence summary of your feature request?
A new admin role that cannot modify global rights and settings but can manage user- and computer-based permissions.
Please describe your idea in detail. What is your problem, why do you feel this idea is the best solution, etc.
Currently, under System Configuration > Administrators Groups, the Device Control group can make changes to both Global Rights and Global Settings. However, in some cases, it is desirable for certain administrators to manage only user- and computer-based permissions without being able to modify global settings. This would protect critical global configurations from unauthorized changes while still allowing necessary permissions for daily operations.
How do you currently solve the challenges you have by not having this feature?
Since this permission separation is not currently possible, some users are not granted any administrator rights at all to prevent changes to global settings. This leads to a lack of flexibility in daily operations and limits task delegation among administrators.