At one point, it was possible to scope users/groups to specific OU's when setting up an admin in Privilege Manager. At some point, that was removed, and the AD and CM sync were set behind an enterprise license. It would be nice to see better RBAC/...