In terms of #3, why is this an assumption? It would seem to me that you could place those users in their own OU, secure it with GPOs any way you’d like and explicitly deny those users to other resources in AD.
Any way you look at it, you’ll have some extra Admin overhead.