- Run the same Ldap queries, as found in the log, from a search in Active Directory, and check if you can find the object(s)
- Check inheritance on the AD objects, you might need to enable it
- Give delegation to the migration account, on the OUs used, as follows:
From Domain Controller, on the OUs involved:
a. right click and choose delegation
b. select the migration account
c. select "Only the following object in the folder"
and select: user objects, group objects and contact object
d. below select also:
Create selected objects in this folder
Delete selected objects in this folder
e. click next and select: Full Control, Read and Write