yup...that's the right, to make it more clear, create a group whatever groupname you like, with account priviledges and administrative rights, then you can modify it there via groupname, not on the default account settings.
pede rin, you make a user the let the user member to that "account" tapos you modify the user's by denying some administrative rights. RULE 1: "Deny options overrides permissions"
secnerio 1:
"ACCOUNT GROUP" - can add/delete/modify users. so whoever members on it can do the same thing.
"USERA" - member of ACCOUNT GROUP, but has and denied of adding users, so by RULE1: it cannot add users.
secnerio 2:
"ACCOUNT GROUP" - all permitted except DELETING USERS:
"USERA" - member of account group have ALL OPTION PERMITTED. even thou all options permitted, still cannot delete users, same thing applied in NTFS, and LOCAL SECURITY.
Hope this helps