SL 2015 CU2, Windows Authentication. Client wants IT Dept to create new SL Users, but not be part of the ADMINISTRATORS Group. Auditors do not want IT Dept to have access to Financial modules. Created an ADMIN group with rights to only System Manager screens, including User Maintenance (95.260.00). User was also assigned sysadmin SQL role directly in SQL Server.
When IT user attempts to create a new SL User, the message received is below. How can we set up the ability for IT to add new SL Users w/out granting ADMINISTRATOR group?