Use the group reference
right to grant delegated admins the right to
see what groups a user is a member of without granting group resource management
rights.
To grant a delegated admin the group reference
right:
Run dsconfig with the
create-delegated-admin-resource-rights option.
dsconfig create-delegated-admin-resource-rights \
--rights-name DArights \
--rest-resource-type groups \
--set enabled:true \
--set admin-permission:reference \
--set admin-scope:all-resources-in-base