I have a requirement to allow a non-admin user to use RH management console. I would like to limit user only to read/search People OU. For user to log into console I placed them in Administrator group but not the Configuration Administrator group. Added user to the directory server object and created new ACI under User and Groups. My test user can make changes to configuration settings such as password policy. How can I limit user only to People OU?