When running the CMN Directory Connector in the Notes to Exchange direction an error, "50 insufficient access", is seen in the log file and no contacts are created in Exchange. Entries similar to the following example may be found in the CMN log file.
The CMN log file can be located on the CMN server: C:\Program Files (x86)\Quest Software\Quest Coexistence Manager for Notes\Directory Connector\log4net\CMN.log
License Key Information : 9/19/2012 9:38:07 PM
Build ID | XXXXXXXXX
Customer | Quest Software
Key Serial | X
Add Struct | cn=CMN,OU=Exchange,DC=test,DC=corp
LDAP Return | 50: Insufficient access
LDAP Message | 00000005: SecErr: DSID-031521D0, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
Error Summary : 9/19/2012 9:38:07 PM
50: Insufficient access | 1
Fatal Error | 1
This error is typically caused by a limited set of permissions granted to the Active Directory account being used by the CMN Directory Connector.
The following excerpt from the CMN Quick Start Guide explains the rights required for the Active Directory account used by the CMN Directory Connector:
An Exchange user account granted membership in Organization Management (for Exchange 2010) or Exchange View-Only Administrators (for Exchange 2007). This user must be added to the ACL for the Windows domain, and must have Create and Delete All Child Objects permissions applied to This object and all descendant objects (domain object Properties | Security tab | Advanced Security Settings | Edit).