Historically we have given our Help Desk admin rights to our tree. We
would like to revolk admin rights and only give them rights they need in
eDirectory to perform their job.

Our tree design has user objects under a user container, workstation objects under a workstation container, and
application objects under a application container, and group objects under
a group container.

Does anyone know what kind of rights are required to associate
applications to users, groups, and workstations? Delete workstation