WinSecWiki > Security Settings > Local Policies > User Rights > User Rights In-Depth > Sync directory service data
Synchronize directory service data
AKA: SeSyncAgentPrivilege, Synchronize directory service data
Default assignment domain controllers: none
What this right is NOT
This right has no effect on workstations and member servers – only on domain controllers. This right has nothing to do with your ability to initiate on-demand synchronizations between domain controllers in Active Directory Sites and Services.
This right is needed in order to use the DirSync. DirSync is an ADSI control that enables an application to periodically poll AD for objects that have changed since the last such search/poll. This is useful for LDAP synchronization tools like Microsoft Identity Integration Server (MIIS)
Back to top