How to grant the "Replicating Directory Changes" permission for the Microsoft Metadirectory Services ADMA service account (303972)
The information in this article applies to:
- Microsoft Metadirectory Services 2.2
- Microsoft Metadirectory Services 2.2 SP1
- Microsoft Identity Integration Feature Pack for Microsoft Windows Server Active Directory
- Microsoft Identity Integration Server 2003 Enterprise Edition
This article was previously published under Q303972 SUMMARY
When discovering objects in Active Directory using the Active Directory management agent (ADMA), the account that is specified for connecting to Active Directory must either have Domain Administrative permissions, belong to the Domain Administrators group, or be explicitly granted Replicating Directory Changes permissions for every domain of the forest that this management agent accesses. This article describes how to explicitly a grant a user account the Replicating Directory Changes permissions on a domain.
Note In Windows Server 2003, the name of this permission changed to "Replicate Directory Changes."
Modification Type: | Major | Last Reviewed: | 7/20/2005 |
---|
Keywords: | kbenv kbhowto KB303972 |
---|
|