
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Minimum permissions needed for reading [pseudo].Member
Hi,
We have eDirectory 9.0.4 and IDM 4.6.2. In one of the drivers, we set Engine Control Values of "Revert to calculated membership value behavior" to False and for reading the nested parent group "Member" values we query [pseudo].Member in one of the policies. It works when the account used in the driver has "Supervisor" permissions in the ACL. But when it changed to just read permissions on "Member", "GroupMember" and "Group Membership" attributes on all users and Groups, it is returning empty results. It is able to read (static) members of the group, but not the nested group members ([pseudo].Member). Any idea what is the minimum permissions needed in the ACL to read nested group's calculated "Member" values ([pseudo].Member)?
Thanks,
Gokul.