Consider the following scenario:
- The Active Directory Recycle Bin is enabled
- Users have been delegated the "All Objects - View or Restore Deleted Objects" Access Template to a specific OU
- The 'This directory object' check box and the 'Child objects of this directory object' is selected on the delegation
- Users have been delegated the "All Objects - View or Restore Deleted Objects" Access Template to the 'Deleted Objects' container
- The 'This directory object' check box is deselected, leaving only 'Child objects of this directory object' selected on the delegation
When attempting to restore a deleted user in the delegated OU, the process completes successfully in the MMC, but gives an Access Denied error in the Web Interface.