I am sorry, I have not experienced anything with Active Directory myself yet, but what you say sounds like the way to go. As you can see, this new role has, I would say, the minimun permissions to just access BP, which is right. Now, an easy way to test that is to create a simple Process that get a crendential with that role and check if you got any exceptions there/or the expected behavior. (Trial and error). Or maybe some in the forum has the answer for your question.