Symptom



Password synchronization doesn’t appear to be working and you find the Event ID 611, source Directory Synchronization, in the event log:



Cause


The Active Directory Domain Services connector (management agent) account needs both of the following extended rights assigned on each in-scope domain naming context/partition:

  • Replicating Directory Changes
  • Replicating Directory Changes All


Resolution

  • Open the Active Directory Users and Computers snap-in
  • On the View menu, click Advanced Features.
  • Right-click the domain object, such as "company.com", and then click Properties.
  • On the Security tab, if the desired user account is not listed, click Add; if the desired user account is listed, proceed to step 7.
  • In the Select Users, Computers, or Groups dialog box, select the desired user account, and then click Add.
  • Click OK to return to the Properties dialog box.
  • Click the desired user account.
  • Click to select the Replicating Directory Changes and Replicating Directory Changes All check boxes from the list.
  • Click Apply, and then click OK.
  • Close the snap-in.