@girish what about just a normal organization level rights separation?
I mean - it's really two different set of roles:
1st line support, dealing with mailboxes
2nd or 3rd, making sure the system and services are up and running.
I don't need hiding anything, I just want to ensure my users can manage they mailboxes and users for they own.
For now I have to temporary give admin permissions to the 1st line and that's kind of risky...