Using REST API /api/ldapdirectories/ requires Master Operator privileges?

I’m attempting to give some access to the API to run GET queries, and most of his queries are working. However, one of the main ones he needs is /api/ldapdirectories/, which is giving him an error “Action requires master operator privileges.” I’ve given him all the access required per documentation here: https://developer.bigfix.com/get-started/who-can-manage.html

Am I missing something for him to be able to reach the ldap directories? I’d rather not give him Master Operator privileges, as that would essentially make him an admin when I only want to give him access to the API.

Why does he need access to the LDAP directory definitions if he is not an admin? These are the details of the defined AD/LDAP directories that your operators are authenticated against when they login. It is intentionally limited to MOs.

He’s part of the internal audit team and would like the information for I assume to see who has access to the application and other information pertaining to the directory/BigFix. If there’s no way around this I can let him know that MO will be needed to access that particular query.

1 Like