There are a handful of special groups that have been granted permissions needed for various projects.
NCSU-Read Group Memberships:
- Root of the Domain – Members, MemberOf, primarygroupID, primarygrouptoken, uidNumber, and gidNumber attributes on descendent User, Computer, Group, and InetOrgPerson objects
- Managed Groups OU – List Contents
NCSU-User Account Managers:
- People OU – Full Control
NCSU-Departmental OU Admins