If an attributeDef is created under folder a:b, then apply privileges to the group of READ,UPDATE to group a:security:admins
If an attributeDef is created under folder a:b, then apply privileges to the group of READ,UPDATE to group a:security:admins