3.1.1.2 ADM_IPAMSecurityGroups
The following are the group object entries that are used for role-based user authorization for the various operations. Each of the entries below has a SID ([MS-DTYP] section 2.4.2) associated with it, which is used for computing the user authorization data as specified in section 3.1.4.3.
IPAM Users
IPAM Administrators
IPAM ASM Administrators
IPAM MSM Administrators
IPAM IP Audit Administrators