What are the AD user rights required for the LDAP Account Unit configuration when it is supposed to be used with Identity Collector?
In the Identity Collector configuration guide, it states:
- Identity collector provides information about users, machines and IP addresses to the Security Gateway. LDAP Account Unit(s) should be configured to allow PDP gateways to perform group lookups on IDs that are provided from Identity Collector to match them to Access Roles.
But all the references to the LDAP Account Unit configuration describe the account as having Admin rights on the domain.
This contradicts the intended deployment model and I do not think it is necessary, if we are simply querying the AD group membership data.