Solution 1:
Delegate permission to object user account who is trying to see the account properties to read the ms-DS-PasswordSetting object under the container domain | System | Password Setting Container and if the FGPP is applying via group also delegate permission to read the group and itself properties.
Recommended using the built-in Access Template "All Object - Read All Properties" to delegate permission on these objects.
Solution 2:
Delegate permission to the user on the top domain using the built-in Access Template All Object - Read All Properties.
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Términos de uso Privacidad Cookie Preference Center