Only applying create, modify, and delete permissions on the /conf folder should work. I created a test user with above permission and adding dam user group default aem OOTB to the the test user and was able to edit existing the metadata and also able to create a new metadata schema. Check the group ...