Active Directory Domain Services was unable to correctly create the default security descriptor for the following application ...

Active Directory Domain Services was unable to correctly create the default security descriptor for the following application directory partition.



Application directory partition: 
%3



User Action

Review the access control list (ACL) on the newly created application directory partition. Ensure the Replication Get Changes All access right is assigned to both the Enterprise Domain Controllers group and the Enterprise Read-only Domain Controllers group, and remove the right from the domain Domain Controllers group.



Additional Data

Error value: 
%1 %2