Have you already import these Active Directory Group to vCOPS?
If YES.
You can create in the "custom-ui" an separate Group with these rights you want for these Active Directory Group.
Image may be NSFW.
Clik here to view.
If you want to grant access in the vSphere webclient it is more complex. You have to create a new Role with the permission for "vCops read only" and put these Role / Group at the top of your vCenter! BUT attention: do not propagate these Role to children