Permissions to do AD Lookups?



What are the proper permissions to grant a user/service account so that they
can do LDAP queries/lookups/etc in Active Directory, but can't do any
damage? I want to give read-only access first, and perhaps one day adjust
the permissions so they can make changes to specific objects.

Thanks!



.


Loading