Grant the service account the correct permissions as per
https://support.quest.com/technical-documents/DOC260525The specific permissions required are the special permissions called:
create serviceConnectionPoint objects and
delete serviceConnectionPoint objects The service account will also require some additional rights to read and create the structure below CN=System,DC=Domain,DC=Com. An easy method to achieve the necessary permissions is to:
1. Grant the service account Full Control to CN=System,DC=Domain,DC=Com
2. Start the MAgE, allow the LDAP hierarchy to be created and the SCP then stop the MAgE
3. Change the permission to Read instead of Full Control
4. Assign the special permissions to CN=Exchange Migration Project,CN=QmmEx,CN=Migration Manager,CN=Quest Software,CN=System,DC=Domain,DC=Com and all child objects.
5. Start the MAgE