Hi, @Anonymous
Thank you for posting in Microsoft Q&A forum.
You may follow this steps:
- Go to the Administration workspace.
- Expand Security, and then select the Administrative Users node.
- Add the AD security group as an administrative user.
- Add the security roles.
- Choose Only the instances of objects that are assigned to the specified security scopes or collections.
- Remove collections All Systems and All Users and User Groups.
- Add the single user collection you want to manage and click OK.
If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Add comment". After the way you tag questions on Q&A is updated, for any "Microsoft Configuration Manager" related problem, you can tag it with "Microsoft Intune", and then "Microsoft Configuration Manager" as the child tag.