WinSecWiki > Security Settings > Local Policies > User Rights > User Rights In-Depth > Sync directory service data

Synchronize directory service data

AKA: SeSyncAgentPrivilege, Synchronize directory service data

Default assignment domain controllers: none

What this right is NOT

This right has no effect on workstations and member servers – only on domain controllers. This right has nothing to do with your ability to initiate on-demand synchronizations between domain controllers in Active Directory Sites and Services. 

This right is needed in order to use the DirSync. DirSync is an ADSI control that enables an application to periodically poll AD for objects that have changed since the last such search/poll. This is useful for LDAP synchronization tools like Microsoft Identity Integration Server (MIIS)

Back to top


Additional Resources