Add Read permission to the account used to authenticate to the LDAP server
- Start the ADSI Edit utility.
- Right click the ADSI Editor icon and click Connect to.
- In the Connection Settings screen, in the Connection Point section, select Select a well known Naming Context and from the drop-down list, select Default naming context.
- Click OK.
- Click your domain.
- Navigate to and expand CN=System.
- Right-click CN=Password Settings Container and click Properties.
- On the Security tab, click Add to add the account, or the user group that the account is a member of, that is used to authenticate to the LDAP server.
- Under Group or user names, with the added account or user group selected, select the Read checkbox in the Allow column.
- Click Apply.
- Click OK.