When using the Lync Server 2010 Control Panel to enable or move an Active Directory, directory service domain user for use with Lync Server 2010 the following errors are returned: Active Directory operation failed on "DC1.contoso.com". You cannot retry this operation: "Insufficient access rights to perform the operation"
Publication Date: December 7, 2010
KB Article: 2466000
Product Version: Lync Server 2010
The error described above is caused by the combination of the following two reasons:
- The user account that is part of the Lync Server 2010 move or enable operation is a member of an Active Directory, directory service protected domain security group. Since the user account belongs to a protected domain security group it is unable to keep the RTCUniversalUserAdmins and RTCuniversalUserReadOnlyGroup Universal Security groups and their permissions as Access Control Entries (ACEs) to the protected domain security group's default Access Control List (ACL).
- The Lync Server 2010 Control Panel is not designed to delegate the permissions that are needed to complete the user account move or enable operation
Click to read the complete article.
Lync Server Resources
- Lync Server 2010 documentation in the TechNet Library
- DrRez blog
- Lync Server and Communications Server resources
We Want to Hear from You
Kelly Brook Robin Tunney Kate Groombridge Dania Ramirez Lucy Liu
No comments:
Post a Comment