You need to create a password policy for the engineering department that is different from your domain password policy
You need to prevent members of the TempWorkers group from accessing the confidential data on the file servers