You should setup server document that user Administrator is not listed in Full Access administrators (for that purpose you can have some other user such as PowerAdmin, etc...) then you should be fine, because administrator can't manage ACL if he is not listed on it. Only full access administrator can manage ACL no matter if he is listed or not. And then you should check mail database ACL that admin is not listed there.