Create a "UMC-only"-Admin which can just create/modify users but cannot do anything to admin-accounts

the problem occurs when accessing

POST https://ucs.mydomain.tld/univention/command/udm/get 403 (Forbidden)"

accessing this url using th ebuiltin administrator works:

https://ucs.mydomain.tld/univention/command/udm/get

I already gave the group “udm-all” in the policies and gave write-permissions to templates in LDAP. but that’s not fixing it.