- key: /client-admins
  displayname: Client Administrators
  explaintext: |
    Define users and groups from AD allowed to administer client machines.
    It must be of the form user@domain or %group@domain. One per line.
  elementtype: multiText
  meta:
    meta: foo
  default: ""
  note: |
    -
     * Enabled: This allows defining Active Directory groups and users with administrative privileges in the box entry.
     * Disabled: This disallows any Active Directory group or user to become an administrator of the client even if it is defined in a parent GPO of the hierarchy tree.
  type: privilege
