Restrict Groups by something other than technician?

Restrict Groups by something other than technician?

I'm still in the trial with this product and love it so far. 
I need my helpdesk to be able to edit ANY AD account that is not a domain admin or an enterprise admin. I know these groups can be restricted per technician but that seems rather inefficient. Is there a way to configure it so that everyone in the "helpdesk" role can't see these groups?

                New to ADSelfService Plus?