I recently came across a question on a forum that asked how to deny enable and disable rights on a user object to a user who otherwise has explicit or inherited permissions to do so. While I don't suggest doing this day to day, if the situation arises here's how you do it. You'll need to go download and add the Quest, now Dell, Active Directory cmdlets\snapin (e.g. Add-PSSnapin quest.activeroles.admanagement). This one-liner below denies user12 userAccountControl access to user13. In other words, user12 will be unable to enable or disable user13's account.
You can now use Get-QADPermission to verify the added access entry.