Restricting Admin users access to modules

Hi,

I know this might sound crazy as admins can access the admin section of the system and change rights… but is there a way of restricting some admins from accessing certain modules.

I have IT who I need to administer day to day changes but I dont want them to necessarily having full access to financial records for the company. I realise by accessing the admin screen they can change the rights themselves but at least if I can set them so they cant see certain modules by default it would be a start.

Also is there an extn that would help?

Any user with admin rights is exempted from Roles and Restrictions put on to them. The best way which I can think of is to create a new security group for the other “admins” with desired restrictions. With this you do not have to worry about them accessing the admin section.

Not sure if I understand correctly. Doesnt a security group require you to assign roles to apply the relevant restrictions? If thats the case and admins are exempted from roles and restrictions wont that be the same as we are now?

I’m sorry I should have been a little more clear. What I was suggesting was to remove the admin status of those users, which I forgot to mention.