I hope you are all well.
Guys, we have a requirement where we want a user called 'Bob', to be able to edit an Active Directory attribute. That attribute is an existing AD attribute called 'primaryTelexNumber'. We dont want to give him domain admin access just to perform this task, so we want to give him the minimal rights required to perform this operation.
Basically, when a new user comes on, Bob needs to be able to change the primaryTelexNumber attribute for this user.
So, we are not extending the schema, we just want to provide Bob with the rights to perform this operation but not give him any more rights than required.