Server Admins using the Server ID to edit the NAB

Im in a bit of a pickle at the moment. We have a number of server administrators that have been using the server id to make changes to the NAB. I would like to lock this down if possible but Im not technically sure how to do it.

If I set a password on the server I would need to give them the password as they administer the server.

I cant lock down their access to the ID because they are Domain admins. How do I lock down access to the NAB?

Subject: ACL

Make sure the ACL has the servers set to a user type of Server. If the servers are in a group make the type Server Group. This should prevent them from using the server ID to make changes via the client. This is because a “server” cannot physically use a client as a user (Person) would. Most likely your servers are not listed as Unspecified or Mixed Group

Subject: Servers are in server only groups

Our servers are in server only groups and listed in the acl of the NAB as “server group”, but if I switch to the server ID I can still make changes.

Subject: Server in Admin Group : (

Sorry guys you were right, there was a rogue group with a server in it.

Thanks