Ldap and root access on workstations


I have what I hope is an easy question ( and I hope this is the right place to post this ).

I have a situation where we are using openldap and a large number of users who also have local root level access to their own workstations.

Is there a way in ldap to allow root access without letting them su to another user ? Is there some ACL that I can put into place that would prevent this ?