Restricting who can onboard a device in ClearPass

I was wondering if there was a way to restrict who may onboard a device in ClearPass?  I have ClearPass Onboard configured to authenticate users via Active Directory, but it seems that if anyone has an AD account, they'll be able to onboard a device.  If I allow that, things could get out of control really quick.


I'd like to restrict that perhaps to just users in a particular AD group, or some other designator.


Anyone know if that's possible?

