I have a SharePoint site set up for collaboration with users outside our company. It is set up in AD account creation mode and is on a perimeter network behind an ISA server. My problem is that I need to prevent internal users from giving admin rights to outside users. I had tried setting up separate virtual servers, directing any traffic coming from outside to the 2nd virtual server. This way, I could use the "Manage User Rights for Virtual Server" page to restrict the specific rights that I did not want external users to have. Unfortunately, when I applied these changes, it applied them to the internal virtual server as well.
My question is this: Is there a way to set up separate virtual servers with different settings for the user rights?
Alternatively, does anyone have a suggestion as to how to accomplish this in another fashion?