Hello,
For users to be able to browse an OU or Container in your Active Directory, they need to be able to read not only the OU/Container they need to manage, but also all OUs/Containers that the managed OU is a child of up to the root domain object. For example, if you want to allow your users to browse the Minnesota Office OU that is located in the example.com domain under Offices/US Offices, you need not only to grant the permissions for the Minnesota Office OU, but also grant at least the Read permissions for the Offices and US Offices OUs, and also for the example.com domain. By default, the permission to read all objects is granted by the built-in Security Role that is called Domain User. However, if you chose to remove the default assignment of this role and grant the Read permission on a more granular level, take a look at the Hide Active Directory Objects from Users tutorial on how to allow your users to see only the objects they need.