Hi @ABDXJ
Have a look at these previous questions, which were trying to achieve same thing.
https://learn.microsoft.com/en-us/answers/questions/707421/ad-search-privileged-groups.html
I would also suggestion having a look at this article on restricting who can join machines to the domain: