
Explanation
The correct sequence to delegate the rights to unlock users to Tier 1 support with an existing LDAP group is as follows:
* Sign into the PWA (V10) as a local user with the "Manage Directory Mapping" privilege.
* Open LDAP Integration view.
* Add Mapping to the existing LDAP integration.
* Name the new mapping and set the mapping order.
* Select required LDAP group and assign authorization "Activate Users".
Comprehensive Explanation: To delegate the rights to unlock users, you must first access the Privileged Web Access (PWA) with the appropriate privileges to manage directory mappings. Then, navigate to the LDAP Integration view to add a new mapping to the existing LDAP integration. This mapping should be named and ordered correctly. Finally, select the LDAP group that represents Tier 1 support and assign the specific authorization needed to unlock users, which is "Activate Users" in this context12.
References:
* CyberArk Docs: LDAP Integration in V102
* CyberArk Knowledge Article: How to delegate permissions to unlock Active Directory accounts1