I noticed that unlike our other update privileges LDAP update does not include read. This means assigning nx-ldap-update alone does not give any access to the UI to perform the functions allowed by update.
Paired with nx-ldap-read this functions as I would expect.
I noticed the same of nx-ldap-create (nx-ldap-delete works as I expected).
I suspect this is a bug/oversight however, there may be a reason. I am filing at least for analysis.