Any good articles on how to lock down a specific user?

I'm reading about the DNS Dynamic update user credientials. I hear it's best practice to create a dedicated user that can ONLY do that job and that is all. I've read 290/291 books and I haven't learned the best practice to very strictly lock down a user account so they can only do specific jobs. Does anyone know of any good articles/tutorials on how to go about doing this? Any help is appreciated. Thanks!
    What they mean is, create a user, and don't add any permissions for anything else. Only use it for DNS. If you do think of something that it shouldn't have, then you can remove it. But users don't have many permissions/rights by default anymore.
