Trying to add delegation for the management of the jpegPhoto attribute to a non-Domain Admin account. This attribute is used for an online employee directory. When modified by a Domain Admin everything works fine and we can assign a JPEG file to the attribute. However, when trying to do this through another account we get the following error:
Unable to save Active Directory data: Access is denied.
-- Extended Error --- LDAP Provider : 00000005: SecErr: DSID-031A0F44, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
I have already gone into AD Users and Computers and delegated the following rights to the user account:
User Objects
Read/Write - jpegPhoto
Read/Write - pwdLastSet
Read/Write - userAccountControl
I've also tried adding Account Operator to the user's membership and still get the same error. What additional settings do I need to have without making the account a member of the Domain Admins group? Thanks in advance.
Unable to save Active Directory data: Access is denied.
-- Extended Error --- LDAP Provider : 00000005: SecErr: DSID-031A0F44, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
I have already gone into AD Users and Computers and delegated the following rights to the user account:
User Objects
Read/Write - jpegPhoto
Read/Write - pwdLastSet
Read/Write - userAccountControl
I've also tried adding Account Operator to the user's membership and still get the same error. What additional settings do I need to have without making the account a member of the Domain Admins group? Thanks in advance.
Comment