3.1.1.3.2.15 pendingPropagations

Returns a set of DNs of objects whose nTSecurityDescriptor attribute (that is, the object's security descriptor) has been updated but the inheritable portion of the update has not yet been propagated to descendant objects (see Security Descriptor Requirements, section 6.1.3). An object is included in the set only if the update that caused the temporary inconsistency in the object's nTSecurityDescriptor was performed on the LDAP connection that is reading the pendingPropagations rootDSE attribute.