Active Roles Users who have been delegated permissions using an Access Template that contains Full Control permissions over a specific class will not be able to create new objects of that class.
The noted exception here is Full Control of Organizational Units or Containers: this delegated permission will allow the creation of any object class within Organizational Unit or Containers, respectively.
The Full Control permission includes full permissions over existing objects of that class, and does not include the permissions necessary to create new objects of that class.
Assigning the Create child objects permission within an Organizational Unit or Container is necessary to delegate the ability to create an object.
© 2024 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy Cookie Preference Center