I would like to setup a helpdesk role that locks the user into a specific OU. The reason behind this is to keep our helpdesks separate and not allow them to query other parts of the AD.
Another part of this, but different issue, would be to remove the ability to query groups and computers by removing the check boxes from the web page.