Before sites can publish to the Active Directory forest, the site server's machine account or the Active Directory forest ...

Before sites can publish to the Active Directory forest, the site server's machine account or the Active Directory forest account must have Full Control permissions to the System container in the forest, and you must extend the Active Directory schema for the forest.