I've question regarding the permission sets flexibility. After trying out a few permission sets configurations I've be unable setup a set in which a user can create a On-Demand Scan task but can't view/create/duplicate/break inheritance in the policies of VirusScan.
My main concern is in the fact that I need to delegate tasks to users (like full scan for example) but I don't want them to mess with the policies, which are defined by Global Admins.
Locking the inheritance is not an option since the lock also affects Global Admins.
Anyone knows of any permissions set configuration that can workaround my problem?