Object rights are not being copied from source to target even though Security descriptor migration rule was set to merge in migration session or synchronization properties. Dsa.log contains one of the following errors:
4/8/2009 10:35:16 AM (GMT+01:00) Target JobID:0 -> object was not created due to error
4/8/2009 10:35:16 AM (GMT+01:00) Common JobID:0 -> LDAP error 0x13. Constraint Violation (0000051B: AtrErr: DSID-03150B5E, #1:
0: 0000051B: DSID-03150B5E, problem 1005 (CONSTRAINT_ATT_TYPE), data 0, Att 20119 (nTSecurityDescriptor) ).
4/8/2009 10:35:17 AM (GMT+01:00) Target JobID:0 -> object was not modified due to error
4/8/2009 10:35:17 AM (GMT+01:00) Common JobID:0 -> Error 0xe1000040. Per attribute apply failed for object
Error 0xe1000041. Apply of attribute nTSecurityDescriptor with value(s) = [long hex string] failed.
LDAP error 0x13. Constraint Violation (0000051B: AtrErr: DSID-0315091A, #1:
0: 0000051B: DSID-0315091A, problem 1005 (CONSTRAINT_ATT_TYPE), data 0, Att 20119 (nTSecurityDescriptor) ).
The issue can be caused by lack of user rights for the QMM service account on the target domain controller. Manage Auditing and Security Log right (SeSecurityPrivilege) and Restore Files and Directories (SeRestorePrivilege) are required to write the ntSecurityDescriptor.
These privileges can be granted via the default domain controller GPO. Logon to domain controller with an administrative account and do the following:
1. Click on Start | Programs | Administrative Tools.
2. Select Domain Controller Security Policy.
3. Navigate to Security Settings | Local Policies | User Rights Assignment.
4. Right-click the right Manage Auditing and Security Log and select Properties.
5. Verify that the target QMM service account has this right. If it does not, please add the account.
6. Repeat steps 4-5 for Restore Files and Directories user right.
Another option is to set the security descriptor migration rule to skip in QMM migration or synchronization properties, but that will prevent source and target security descriptors from being merged.