User management delegation

is there a way to define a user in UCS that is able to modify all other users in a domain (via UMC) but not able to change anything else in the system, i.e. can access (in read/write mode so to say …) the users UCM module but no other module?