i am running a domain controller system having active directory.AD users are only members of domain users.users can not share folders on their computer being domain users and they can not install any thing.but if i make them member of domain admin (which is not good practice)they can perform these jobs.what should i do to users have these permissions without giving them admin rights?