Active Directory Lightweight Directory Services was unable to correctly create the default security descriptor for the following ...

Active Directory Lightweight Directory Services was unable to correctly create the default security descriptor for the following application directory partition. 
 
Application directory partition: 
%3 
 
User Action 
Review the access control list (ACL) on the newly created application directory partition. Ensure the Replication Get Changes All access right is assigned to both the Enterprise Domain Controllers group and the Enterprise Read-only Domain Controllers group, and remove the right from the domain Domain Controllers group. 
 
Additional Data 
Error value: 
%1 %2