Any good articles on how to lock down a specific user?

I'm reading about the DNS Dynamic update user credientials. I hear it's best practice to create a dedicated user that can ONLY do that job and that is all. I've read 290/291 books and I haven't learned the best practice to very strictly lock down a user account so they can only do specific jobs. Does anyone know of any good articles/tutorials on how to go about doing this? Any help is appreciated. Thanks!
“For success, attitude is equally as important as ability.” - Harry F. Banks
Comments