How to manage Active Directory Domain User accounts via PUPM?

Question asked by klauspm on Aug 5, 2013
I've got several Active Directory domain user accounts spread across several domains within our forest. These are sensitive accounts that we'd like to start vaulting with Enterprise Management. I've been partially successful by adding a 'Windows Agentless' endpoint for each domain controller with an account that is a 'Domain Admin' on that particular domain. I can then vault the domain accounts I want to within that domain. Problem is, I won't be allowed to use a 'Domain Admin' account to manage these, as our enterprise desires to limit security risks. Is there another way I can accomplish this?

Note that we're currently using Enterprise Management 12.6 SP1 with the embedded user store.