The actions that administrator users can perform (manage users, computers and groups, as well as configure and uninstall the protection), are restricted to those computers or groups they have created or have permissions on.
Administrator users can:
Change their own credentials.
Create users.
Administrator users can:
Create search tasks launched from those computers on which they have permissions.
View and/or delete any of the previously created search tasks but only from computers in groups on which they have permissions.
Administrator users can:
Create manual or automatic groups/subgroups, and configure the protection profiles of the groups on which they have permissions. Administrator users cannot access a child group if they do not have access to the relevant parent group.
Delete the groups on which they have permissions. You can only delete groups that don't have any computers inside, that is, prior to deleting a group/subgroup you must assign or move its computers to another group/subgroup. Once you have emptied the group/subgroup, you can delete it.
Edit the Comments field of those computers on which they have permissions, in the Computer details window.
Remotely access computers that belong to groups on which they have permissions.
Administrator users can:
Configure uninstall tasks for those computers and groups on which they have permissions.
View and/or delete uninstall taks, but only on computers belonging to groups on which they have permissions.
Administrator users can:
Create and view new profiles.
Create copies of profiles on which they have permissions and view them.
Configure scheduled scans of specific paths for profiles on which they have permissions or which they have created.
View reports (immediate reports, not scheduled ones) about groups on which they have permissions, provided those permissions apply to all the groups covered in the report.
Create tasks to send scheduled reports about groups they have permissions on.
View tasks to send scheduled reports about groups they have permissions on, provided those permissions apply to all the groups covered in the report. Otherwise they will not be able to view the report sending task.