Active Directory synchronization reports: The user logged on to the directory has insufficient read rights on some objects.
Known to apply to the following Sophos product(s) and version(s)
SafeGuard Management Center / Local Policy Editor
What To Do
The account used for the import and synchronization needs 'Read' rights for the domain and all child objects.
Assign rights as follows:
- Open the 'Active Directory Users and Computers' management window, and go to "Advanced Features".
- For the domain, select 'Properties'
- Add a user (or a group) and click the 'Allow' checkbox to assign the "Read" permission.
- Click on the "Advanced" button, select the user (or group) and press the "Edit..." button
- In the 'Permission Entry for utimaco', from the "Apply onto" drop-down, select "This object and all child objects"
The result should look like this: