I have a sharepoint 2013 server setup, and we want user's photo to sync from sharepoint into active directory.
We have setup an AD connection and everything seems to sync fine apart from the photos. When looking in the event viewer we are getting event ID 6100, and in the miis client, we are getting "permissions issue - insufficient rights to perform the operation"
The synchronisation account has the following permission on the domain:
Relicating Directory Changes
Create all child objects