In the subject of the ACI, the ($dn) macro is replaced by the entire substring that matches in the target. For example:
The subject becomes this:
After the macro has been expanded, Directory Server evaluates the ACI following the normal process to determine whether access is granted.
Unlike a standard ACI, an ACI that uses macro substitution does not necessarily grant access to the child of the targeted entry. This is because when the child DN is the target, the substitution might not create a valid DN in the subject string.