Even though Migration and Synchronization are functional, Group Memberships are not updating on the target groups.
Link Resolver Log
26/10/2016 16:34:59 1980 4628 Creating new connection to , 389
26/10/2016 16:34:59 1980 4628 LDAP Error 0x52. Local error occurred.
26/10/2016 16:34:59 1980 4628 Finish resolving links for object LDAP://
Even though this account has full rights to ADAM, the SPN attribute for the ADAM instance is either missing or incorrect. Link resolver uses a different method to access the ADAM database than the Directory Synchronization Agent.
The issue can be caused by incorrect Service Principal Name entries on the Service account. These entries are sometimes left over if the account in question was ever used to Install an ADAM-AD LDS Instance.
This can also be caused by the ADLDS Instance running under the wrong security context.
Resolution 1
Clearing the incorrect values in the SPN attribute for the existing Service Account and adding the correct values for the current ADAM instance
Resolution 2
Recreating the Service account would be the easiest method and then granting access through the Migration Manager Console.
Resolution 3
If the ADLDS Instance service is set to run under any context other than the Service Account, then change the Log On to the Service Account and restart the Instance service.