You can't recreate those groups exactly [ not even close to administrators]
but if all the user needs if the proper file/folder/registry permissions
then you could configure that so that the user can have access. There is not
foolproof way to not allow power users to be able to create user accounts as
it is hard coded into the operating system and not a user right/privilege.
You could try applying the compatws.inf security template to a test computer
to see if that works which gives the users group the same file/registry
permissions as power users and then in Local Security Policy give users the
same user rights as power users which I believe would only be profile a
singe system process and change system time but having said that if you are
obligated to do the testing as a power user or administrator you may have to
live with that and the associated inconveniences. --- Steve
http://support.microsoft.com/?kbid=269259 --- works for XP Pro also
http://www.microsoft.com/technet/prodtechnol/windows2000serv/maintain/security/secdefs.mspx